PT-2025-43134 · Gitlab · Gitlab Ce/Ee

Published

2025-10-22

·

Updated

2025-11-01

·

CVE-2025-10497

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 17.10 through 18.3.4 GitLab CE/EE versions 18.4 through 18.4.2 GitLab CE/EE versions 18.5 through 18.5.0
Description An issue in GitLab CE/EE could allow an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads. The issue relates to the unlimited allocation of resources. The vulnerability impacts event collection.
Recommendations GitLab versions prior to 18.3.5 should be updated. GitLab versions prior to 18.4.3 should be updated. GitLab versions prior to 18.5.1 should be updated.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-13373
BIT-GITLAB-2025-10497
CVE-2025-10497

Affected Products

Gitlab Ce/Ee