PT-2025-50574 · Gitlab · Gitlab Ce/Ee

Thong Kuah

·

Published

2025-12-10

·

Updated

2025-12-23

·

CVE-2025-14157

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 6.3 through 18.4.5 GitLab CE/EE versions 18.5 through 18.5.3 GitLab CE/EE versions 18.6 through 18.6.1
Description An authenticated user could potentially cause a Denial of Service condition by sending specially crafted API calls containing large content parameters. The issue affects the processing of API requests with oversized data, potentially leading to resource exhaustion or service disruption.
Recommendations Update GitLab CE/EE to version 18.4.6 or later. Update GitLab CE/EE to version 18.5.4 or later. Update GitLab CE/EE to version 18.6.2 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-15827
BIT-GITLAB-2025-14157
CVE-2025-14157

Affected Products

Gitlab Ce/Ee