CVE-2025-12576: Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that under certain conditions could have allowed an authenticated user to cause a denial of service due to improper handling of webhook response data.
Other sources
GitLab has remediated an issue that under certain conditions could have allowed an authenticated user to cause a denial of service condition due to improper handling of webhook response data.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-12576?
CVE-2025-12576 has been classified as a medium severity vulnerability.
How do I fix CVE-2025-12576?
To fix CVE-2025-12576, upgrade GitLab to versions 18.7.6, 18.8.6, or 18.9.2 or later.
What versions of GitLab are affected by CVE-2025-12576?
CVE-2025-12576 affects GitLab CE/EE versions from 9.3 up to but not including 18.7.6, 18.8 up to but not including 18.8.6, and 18.9 up to but not including 18.9.2.
What issues does CVE-2025-12576 cause?
CVE-2025-12576 can allow an authenticated user to cause a denial of service under certain conditions.
Who is the vendor for CVE-2025-12576?
The vendor for CVE-2025-12576 is GitLab.