PT-2025-43139 · Gitlab · Gitlab Ce/Ee

Published

2025-10-22

·

Updated

2025-10-28

·

CVE-2025-11974

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 11.7 through 18.3.5 GitLab CE/EE versions 18.4 through 18.4.3 GitLab CE/EE versions 18.5 through 18.5.1
Description An unauthenticated attacker could create a denial of service condition by uploading large files to specific API endpoints. The issue impacts GitLab CE/EE.
Recommendations Update GitLab CE/EE to version 18.3.5 or later. Update GitLab CE/EE to version 18.4.3 or later. Update GitLab CE/EE to version 18.5.1 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-13374
BIT-GITLAB-2025-11974
CVE-2025-11974

Affected Products

Gitlab Ce/Ee