MEDIUM
CVE-2025-5996
CVSS
6.5
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 2.1.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. A lack of input validation in HTTP responses could allow an authenticated user to cause denial of service.
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
0.76%
Probability of exploitation in next 30 days
53.9th percentile
References
https://gitlab.com/gitlab-org/gitlab/-/issues/476671
Exploit, Issue Tracking
https://gitlab.com/gitlab-org/gitlab/-/issues/479167
Exploit, Issue Tracking
https://gitlab.com/gitlab-org/gitlab/-/issues/483111
Exploit, Issue Tracking
https://gitlab.com/gitlab-org/gitlab/-/issues/483150
Broken Link
https://gitlab.com/gitlab-org/gitlab/-/issues/498649
Broken Link
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.