CVE-2025-14511: Improper Validation of Specified Quantity in Input in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted files to the container registry event endpoint under certain conditions.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to cause denial of service by sending specially crafted files to the container registry event endpoint under certain conditions.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-14511?
CVE-2025-14511 is classified as a Denial of Service vulnerability affecting certain versions of GitLab.
How do I fix CVE-2025-14511?
To remediate CVE-2025-14511, upgrade to GitLab versions 18.7.5, 18.8.5, or 18.9.1.
Which versions of GitLab are affected by CVE-2025-14511?
CVE-2025-14511 affects GitLab versions from 12.2 up to but not including 18.7.5, 18.8 up to but not including 18.8.5, and 18.9 up to but not including 18.9.1.
Can an unauthenticated user exploit CVE-2025-14511?
Yes, an unauthenticated user can exploit CVE-2025-14511 to cause a denial of service.
Who is the vendor for CVE-2025-14511?
The vendor for CVE-2025-14511 is GitLab.