CVE-2025-0186: Denial of Service issue in discussions endpoint impacts GitLab CE/EE
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service under certain conditions by exhausting server resources by making crafted requests to a discussions endpoint.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to cause denial of service under certain conditions by exhausting server resources by making crafted requests to a discussions endpoint.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0186?
CVE-2025-0186 is classified as a Denial of Service vulnerability.
How do I fix CVE-2025-0186?
To remediate CVE-2025-0186, upgrade to GitLab versions 18.9.6, 18.10.4, or 18.11.1 or later.
Who is affected by CVE-2025-0186?
CVE-2025-0186 affects all versions of GitLab CE and EE from 10.6 up to but not including 18.9.6, 18.10 up to but not including 18.10.4, and 18.11 up to but not including 18.11.1.
What is the impact of CVE-2025-0186?
The impact of CVE-2025-0186 allows an authenticated user to cause a Denial of Service.
When was CVE-2025-0186 reported?
CVE-2025-0186 was reported and subsequently remediated by GitLab.