CVE-2025-14157: Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a Denial of Service condition by sending crafted API calls with large content parameters.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to cause a Denial of Service condition by sending crafted API calls with large content parameters.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-14157?
CVE-2025-14157 is classified as a moderate severity vulnerability that could result in a Denial of Service condition.
How do I fix CVE-2025-14157?
To fix CVE-2025-14157, upgrade GitLab to version 18.6.2 or later.
What could exploitation of CVE-2025-14157 lead to?
Exploitation of CVE-2025-14157 could allow an authenticated user to cause a Denial of Service by sending crafted API calls.
Which versions of GitLab are affected by CVE-2025-14157?
CVE-2025-14157 affects GitLab versions prior to 18.4.6, 18.5.4, and 18.6.2.
Is the CVE-2025-14157 vulnerability remote or local?
CVE-2025-14157 is considered a local vulnerability since it requires authentication for exploitation.