CVE-2025-0993: Allocation of Resources Without Limits or Throttling in GitLab
Published May 21, 2025
·Updated
An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.
Affected Software
11 affected componentsFixes available
GitLab GitLab CE<17.10.7
GitLab GitLab EE<17.10.7
GitLab GitLab EE>17.11<17.11.3
GitLab GitLab EE>18.0<18.0.1
GitLab GitLab<17.10.7
GitLab GitLab<17.10.7
GitLab GitLab>=17.11.0<17.11.3
GitLab GitLab>=17.11.0<17.11.3
GitLab GitLab=18.0.0
GitLab GitLab=18.0.0
GitLab GitLab>=17.11<17.11.3, >=18.0<18.0.1
17.11.318.0.1
Remediation
Information
Upgrade to versions 17.10.7, 17.11.3, 18.0.1 or above.
Event History
May 22, 2025
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
RemedyDescriptionSeverityWeakness
Apr 22, 2026
Data Sourced
via GitLab·08:55 AM
DescriptionSeverityAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-0993?
CVE-2025-0993 has a high severity rating due to its potential to cause denial of service conditions.
2
How do I fix CVE-2025-0993?
To fix CVE-2025-0993, upgrade to GitLab versions 17.10.7, 17.11.3, or 18.0.1 or later.
3
Who is affected by CVE-2025-0993?
CVE-2025-0993 affects all versions of GitLab CE and EE prior to the specified fixed versions.
4
What type of attack is associated with CVE-2025-0993?
CVE-2025-0993 is associated with a resource exhaustion attack leading to a denial of service.
5
Is CVE-2025-0993 an authenticated vulnerability?
Yes, CVE-2025-0993 requires authentication to exploit the denial of service condition.