HIGH

CVE-2025-10497

Gitlab GitLab 2025-10-27 CVSS v3.1
CVSS
7.5

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.

Summary dbcve.org

A denial of service vulnerability in GitLab CE/EE versions prior to 18.3.5, 18.4.3, and 18.5.1 allows unauthenticated attackers to send specially crafted payloads that can cause the service to become unavailable. The vulnerability requires no authentication, making it easily exploitable.

Mitigation

Upgrade GitLab to version 18.3.5, 18.4.3, 18.5.1 or later to apply the patch. Consider implementing rate limiting or web application firewall rules as a temporary mitigation if immediate upgrade is not feasible.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

0.6%
Probability of exploitation in next 30 days
47.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE