CVE-2025-11447: Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending GraphQL requests with crafted JSON payloads.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to cause a denial of service condition by sending GraphQL requests with crafted JSON payloads.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11447?
CVE-2025-11447 has been classified with a severity that indicates it could lead to a denial of service condition.
How do I fix CVE-2025-11447?
To mitigate CVE-2025-11447, users should upgrade to GitLab version 18.5.1 or later.
Which versions of GitLab are affected by CVE-2025-11447?
CVE-2025-11447 affects GitLab versions prior to 18.3.5, 18.4.3, and 18.5.1.
Can CVE-2025-11447 be exploited by authenticated users?
CVE-2025-11447 can be exploited by unauthenticated users, allowing them to send specially crafted GraphQL requests.
What kind of issue does CVE-2025-11447 address?
CVE-2025-11447 addresses a vulnerability that could lead to a denial of service through crafted JSON payloads.