CVE-2025-0639: Allocation of Resources Without Limits or Throttling in GitLab
An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.
Other sources
An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1. This is a medium severity issue (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, 6.5). It is now mitigated in the latest release and is assigned CVE-2025-0639.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0639?
CVE-2025-0639 is classified as affecting service availability in certain versions of GitLab CE/EE.
How do I fix CVE-2025-0639?
To mitigate CVE-2025-0639, update GitLab CE/EE to versions 17.9.7 or later, 17.10.5 or later, or 17.11.1 or later.
Which versions are vulnerable to CVE-2025-0639?
CVE-2025-0639 affects GitLab CE versions from 16.7 to before 17.9.7, and GitLab EE versions from 17.10 to before 17.10.5 and from 17.11 to before 17.11.1.
What type of issue is described in CVE-2025-0639?
CVE-2025-0639 describes an issue affecting service availability via issue preview in GitLab.
Is CVE-2025-0639 an issue in both GitLab CE and EE?
Yes, CVE-2025-0639 impacts both GitLab Community Edition (CE) and GitLab Enterprise Edition (EE).