CVE-2025-10497
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.
Summary dbcve.org
A denial of service vulnerability in GitLab CE/EE versions prior to 18.3.5, 18.4.3, and 18.5.1 allows unauthenticated attackers to send specially crafted payloads that can cause the service to become unavailable. The vulnerability requires no authentication, making it easily exploitable.
Mitigation
Upgrade GitLab to version 18.3.5, 18.4.3, 18.5.1 or later to apply the patch. Consider implementing rate limiting or web application firewall rules as a temporary mitigation if immediate upgrade is not feasible.