CVE-2025-10858: Allocation of Resources Without Limits or Throttling in GitLab
An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that allows unauthenticated users to cause a Denial of Service (DoS) condition while uploading specifically crafted large JSON files.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to render a GitLab instance unresponsive to legitimate users by sending specifically crafted JSON files.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10858?
CVE-2025-10858 is classified as a critical vulnerability due to its potential to cause Denial of Service (DoS) for unauthenticated users.
How do I fix CVE-2025-10858?
To mitigate CVE-2025-10858, upgrade to GitLab CE/EE version 18.2.7 or later, or 18.3.3 or later, or 18.4.1 or later.
What are the affected versions for CVE-2025-10858?
CVE-2025-10858 affects all versions of GitLab CE/EE prior to 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1.
Who can exploit CVE-2025-10858?
CVE-2025-10858 can be exploited by unauthenticated users, allowing them to trigger a DoS condition.
What type of attack is associated with CVE-2025-10858?
CVE-2025-10858 is associated with a Denial of Service (DoS) attack resulting from the uploading of specially crafted large JSON files.