CVE-2025-14157
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a Denial of Service condition by sending crafted API calls with large content parameters.
Summary dbcve.org
An authenticated user can cause a Denial of Service condition by sending crafted API calls with large content parameters to vulnerable GitLab CE/EE installations. The vulnerability exists in the API handling layer where large content is not properly validated or limited.
Mitigation
Upgrade GitLab to version 18.4.6, 18.5.4, 18.6.2 or later. Alternatively, implement API request size limits at the web server or load balancer level as a compensating control until upgrade can be performed.