CVE-2025-13929: Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by issuing specially crafted requests to repository archive endpoints under certain conditions.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to cause a denial of service condition by issuing specially crafted requests to repository archive endpoints under certain conditions.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-13929?
CVE-2025-13929 has been classified as a denial of service vulnerability that can affect the availability of GitLab instances.
How do I fix CVE-2025-13929?
To remediate CVE-2025-13929, update GitLab to version 18.7.6 or later, 18.8.6 or later, or 18.9.2 or later.
What versions of GitLab are affected by CVE-2025-13929?
CVE-2025-13929 affects GitLab CE/EE versions from 10.0 through to versions prior to 18.7.6, 18.8.6, and 18.9.2.
Can CVE-2025-13929 be exploited by authenticated users?
No, CVE-2025-13929 can be exploited by unauthenticated users, leading to a denial of service.
What type of attack does CVE-2025-13929 enable?
CVE-2025-13929 enables a denial of service attack by allowing specially crafted requests to overwhelm the server.