MEDIUM

CVE-2025-14157

Gitlab GitLab 2025-12-11 CVSS v3.1
CVSS
6.5

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a Denial of Service condition by sending crafted API calls with large content parameters.

Summary dbcve.org

An authenticated user can cause a Denial of Service condition by sending crafted API calls with large content parameters to vulnerable GitLab CE/EE installations. The vulnerability exists in the API handling layer where large content is not properly validated or limited.

Mitigation

Upgrade GitLab to version 18.4.6, 18.5.4, 18.6.2 or later. Alternatively, implement API request size limits at the web server or load balancer level as a compensating control until upgrade can be performed.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

0.31%
Probability of exploitation in next 30 days
24.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE