CVE-2025-0673: Loop with Unreachable Exit Condition ('Infinite Loop') in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an attacker to trigger an infinite redirect loop, potentially leading to a denial of service condition.
Other sources
GitLab has remediated an issue that could have allowed a successful attacker to deny access to legitimate users of the targeted system by triggering an infinite redirect loop causing memory exhaustion on the server.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0673?
CVE-2025-0673 is classified as a high-severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2025-0673?
To mitigate CVE-2025-0673, upgrade GitLab CE/EE to version 17.10.8, 17.11.4, or 18.0.2 or later.
What versions are affected by CVE-2025-0673?
CVE-2025-0673 affects GitLab CE/EE versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2.
What type of attack does CVE-2025-0673 enable?
CVE-2025-0673 allows an attacker to exploit an infinite redirect loop, potentially causing a denial of service condition.
What is the impact of CVE-2025-0673 on services?
The impact of CVE-2025-0673 can lead to service disruptions due to the denial of service from an infinite redirect scenario.