CVE-2025-11974: Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to create a denial of service condition by uploading large files to specific API endpoints.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11974?
CVE-2025-11974 has a high severity level due to its potential to cause a denial of service condition.
How do I fix CVE-2025-11974?
To fix CVE-2025-11974, upgrade GitLab to version 18.5.2 or higher.
Which versions of GitLab are affected by CVE-2025-11974?
CVE-2025-11974 affects GitLab versions from 11.7 to 18.3.5, 18.4.0 to 18.4.3, and 18.5.0 to 18.5.1.
What type of vulnerability is CVE-2025-11974?
CVE-2025-11974 is a denial of service vulnerability that can be exploited by unauthenticated users.
Can unauthenticated users exploit CVE-2025-11974?
Yes, unauthenticated users can exploit CVE-2025-11974 by uploading large files to specific API endpoints.