PT-2026-21990 · Gitlab · Gitlab Ce/Ee

Published

2026-02-25

·

Updated

2026-03-02

·

CVE-2025-3525

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 9.0 through 18.7.4 GitLab CE/EE versions 18.8 through 18.8.4 GitLab CE/EE versions 18.9 through 18.9.0
Description An authenticated user with specific access permissions could potentially cause a Denial of Service. This can occur by creating specially crafted CI triggers through the API. The API endpoint used in the attack is not specified. The vulnerable component is related to CI triggers.
Recommendations Update GitLab CE/EE to version 18.7.5 or later. Update GitLab CE/EE to version 18.8.5 or later. Update GitLab CE/EE to version 18.9.1 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2026-03430
BIT-GITLAB-2025-3525
CVE-2025-3525

Affected Products

Gitlab Ce/Ee