PT-2025-41372 · Gitlab · Gitlab Ce/Ee

Ppee

·

Published

2025-07-17

·

Updated

2025-10-20

·

CVE-2025-2934

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 5.2 through 18.2.8 GitLab CE/EE versions 18.3 through 18.3.4 GitLab CE/EE versions 18.4 through 18.4.2
Description An authenticated attacker could create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses.
Recommendations Update GitLab CE/EE to version 18.2.9 or later. Update GitLab CE/EE to version 18.3.5 or later. Update GitLab CE/EE to version 18.4.3 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-14457
BIT-GITLAB-2025-2934
CVE-2025-2934

Affected Products

Gitlab Ce/Ee