PT-2026-1692 · Gitlab · Gitlab Ce/Ee

Published

2026-01-07

·

Updated

2026-01-22

·

CVE-2025-10569

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 8.3 through 18.5.4 GitLab CE/EE versions 18.6 through 18.6.2 GitLab CE/EE versions 18.7 through 18.7.0
Description An authenticated user could create a denial of service condition by providing crafted responses to external API calls. The issue affects the GitLab import functionality.
Recommendations GitLab versions 8.3 through 18.5.4 should be updated to version 18.5.5 or later. GitLab versions 18.6 through 18.6.2 should be updated to version 18.6.3 or later. GitLab versions 18.7 through 18.7.0 should be updated to version 18.7.1 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2026-00413
BIT-GITLAB-2025-10569
CVE-2025-10569

Affected Products

Gitlab Ce/Ee