CVE-2025-13436: Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when handling certain CI-related inputs.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when handling certain CI-related inputs.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-13436?
CVE-2025-13436 is a Denial of Service vulnerability that affects certain versions of GitLab CE/EE.
How do I fix CVE-2025-13436?
To remediate CVE-2025-13436, update GitLab to a version beyond 18.10.1, 18.9.3, or 18.8.7 depending on your current version.
What versions of GitLab are affected by CVE-2025-13436?
CVE-2025-13436 affects GitLab versions from 13.7 to 18.8.7, 18.9 excluding 18.9.3, and 18.10 excluding 18.10.1.
Can CVE-2025-13436 be exploited remotely?
CVE-2025-13436 requires authenticated user access to exploit, which could lead to a denial of service.
What are the potential impacts of CVE-2025-13436?
The potential impact of CVE-2025-13436 is excessive resource consumption, leading to application downtime or service unavailability.