PT-2025-43135 · Gitlab · Gitlab Ce/Ee+1

CVE-2025-11447

·

Published

2025-10-22

·

Updated

2025-11-01

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 11.0 through 18.3.4 GitLab CE/EE versions 18.4 through 18.4.2 GitLab CE/EE versions 18.5 through 18.5.0
Description An issue has been resolved in GitLab CE/EE that could allow an unauthenticated attacker to cause a denial of service condition. This is achieved by sending crafted JSON payloads within GraphQL requests. The issue relates to unrestricted resource allocation during JSON file processing.
Recommendations GitLab CE/EE versions 11.0 through 18.3.4 should be updated to version 18.3.5 or later. GitLab CE/EE versions 18.4 through 18.4.2 should be updated to version 18.4.3 or later. GitLab CE/EE versions 18.5 through 18.5.0 should be updated to version 18.5.1 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13345
BIT-GITLAB-2025-11447
CVE-2025-11447

Affected Products

Gitlab
Gitlab Ce/Ee