CVE-2024-7803: Allocation of Resources Without Limits or Throttling in GitLab
Published May 21, 2025
·Updated
An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause DoS.
Affected Software
11 affected componentsFixes available
GitLab GitLab CE>=11.6, <17.10.7
GitLab GitLab EE>=11.6, <17.10.7
GitLab GitLab EE>=17.11, <17.11.3
GitLab GitLab EE>=18.0, <18.0.1
GitLab GitLab>=11.6.0<17.10.7
GitLab GitLab>=11.6.0<17.10.7
GitLab GitLab>=17.11.0<17.11.3
GitLab GitLab>=17.11.0<17.11.3
GitLab GitLab=18.0.0
GitLab GitLab=18.0.0
GitLab GitLab>=11.6<17.10.7, >=17.11<17.11.3, >=18.0<18.0.1
17.10.717.11.318.0.1
Remediation
Information
Upgrade to versions 17.10.7, 17.11.3, 18.0.1 or above.
Event History
May 23, 2025
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Apr 22, 2026
Data Sourced
via GitLab·08:55 AM
DescriptionSeverityAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-7803?
CVE-2024-7803 is classified as a denial-of-service vulnerability.
2
How do I fix CVE-2024-7803?
To mitigate CVE-2024-7803, upgrade GitLab CE/EE to version 17.10.7 or later, version 17.11.3 or later, or version 18.0.1.
3
Which versions of GitLab are affected by CVE-2024-7803?
CVE-2024-7803 affects GitLab CE and EE versions prior to 17.10.7, 17.11.3, and 18.0.1.
4
What type of attack does CVE-2024-7803 facilitate?
CVE-2024-7803 can be exploited to perform a denial-of-service (DoS) attack through a Discord webhook integration.
5
Is there any public report available for CVE-2024-7803?
Yes, information about CVE-2024-7803 can be found in public issue reports on GitLab.