CVE-2025-10497: Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to cause a denial of service condition by sending specially crafted payloads.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10497?
CVE-2025-10497 has a medium severity level due to its potential to cause a denial of service.
How do I fix CVE-2025-10497?
To fix CVE-2025-10497, upgrade to the latest versions of GitLab: 18.3.5, 18.4.3, or 18.5.1.
What impact does CVE-2025-10497 have on affected systems?
CVE-2025-10497 can enable an unauthenticated user to launch a denial of service attack on affected GitLab installations.
Which versions of GitLab are affected by CVE-2025-10497?
Versions 17.10 to 18.3.5, 18.4 to 18.4.3, and 18.5 to 18.5.1 of GitLab are affected by CVE-2025-10497.
Is there a workaround for CVE-2025-10497?
There is no documented workaround for CVE-2025-10497; the only resolution is to apply the recommended updates.