Multiple Gitlab Security Vulnerabilities Let Attackers Trigger DoS Condition
GitLab has released urgent updates for its Community Edition (CE) and Enterprise Edition (EE) to address multiple critical security vulnerabilities. The patch versions 18.5.1, 18.4.3, and 18.3.5 resolve several high-severity denial-of-service (DoS)…
GitLab has released urgent updates for its Community Edition (CE) and Enterprise Edition (EE) to address multiple critical security vulnerabilities. The patch versions 18.5.1, 18.4.3, and 18.3.5 resolve several high-severity denial-of-service (DoS) vulnerabilities.
The updates fix issues related to specially crafted payloads that can overwhelm systems, as well as access control and authorization bugs affecting authenticated users. GitLab recommends immediate upgrades for all self-managed installations. GitLab.com users and Dedicated customers are not affected.
CVE-2025-10497: Affects event collection, allowing unauthenticated users to send crafted payloads that exhaust resources. This vulnerability impacts CE/EE versions from 17.10 and carries a CVSS score of 7.5. CVE-2025-11447: Exploits JSON validation in GraphQL requests, enabling unauthenticated actors to flood systems with malicious payloads starting from version 11.0. It also has a CVSS score of 7.5. CVE-2025-11974: Occurs during file uploads to specific API endpoints, where large files from unauthenticated sources consume excessive resources. It affects versions from 11.7 and has a CVSS score of 6.5.
These vulnerabilities were reported through GitLab's HackerOne program or discovered internally, highlighting exposure to event processing, data validation, and upload mechanisms.
GitLab has released urgent updates for its Community Edition (CE) and Enterprise Edition (EE) to address multiple critical security vulnerabilities.
CVE-2025-11702: A high-severity improper access control in the runner API for EE, allowing authenticated users to hijack runners across projects (CVSS 8.5). CVE-2025-11971: Fixes incorrect authorization in CE pipeline builds, allowing unauthorized executions via commit manipulation (CVSS 6.5). Lower-severity issues include business logic errors in EE group memberships (CVE-2025-6601, CVSS 3.8) and missing authorizations in quick actions (CVE-2025-11989, CVSS 3.7).
The patches are part of GitLab's biannual update schedule, with full details available 30 days post-release on their issue tracker. Additional bug fixes address Redis gem downgrades, connection pool errors, and Geo routing leaks.
GitLab strongly advises upgrading all affected self-managed instances immediately to mitigate these risks. This applies to Omnibus, source, and Helm deployments. Regular patching is essential for maintaining security, as outlined in GitLab's handbook. No exploits have been reported, but proactive updates can prevent potential disruptions.
Based on reporting by Cyber Security News.
