PT-2025-43135 · Gitlab · Gitlab Ce/Ee

Published

2025-10-22

·

Updated

2025-11-01

·

CVE-2025-11447

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 11.0 through 18.3.4 GitLab CE/EE versions 18.4 through 18.4.2 GitLab CE/EE versions 18.5 through 18.5.0
Description An issue has been resolved in GitLab CE/EE that could allow an unauthenticated attacker to cause a denial of service condition. This is achieved by sending crafted JSON payloads within GraphQL requests. The issue relates to unrestricted resource allocation during JSON file processing.
Recommendations GitLab CE/EE versions 11.0 through 18.3.4 should be updated to version 18.3.5 or later. GitLab CE/EE versions 18.4 through 18.4.2 should be updated to version 18.4.3 or later. GitLab CE/EE versions 18.5 through 18.5.0 should be updated to version 18.5.1 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-13345
BIT-GITLAB-2025-11447
CVE-2025-11447

Affected Products

Gitlab Ce/Ee