CVE-2025-14513: Improper Validation of Specified Quantity in Input in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially crafted JSON payloads in the protected branches API.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially crafted JSON payloads in the protected branches API.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-14513?
CVE-2025-14513 is considered a denial of service vulnerability.
How do I fix CVE-2025-14513?
To remediate CVE-2025-14513, upgrade GitLab to versions 18.7.6, 18.8.6, or 18.9.2.
Which versions of GitLab are affected by CVE-2025-14513?
CVE-2025-14513 affects GitLab CE/EE versions from 16.11 up to but not including 18.7.6, 18.8 up to 18.8.6, and 18.9 up to 18.9.2.
Who can exploit CVE-2025-14513?
CVE-2025-14513 can be exploited by unauthenticated users.
What type of attack is CVE-2025-14513 associated with?
CVE-2025-14513 is associated with a denial of service attack.