CVE-2025-1477: Allocation of Resources Without Limits or Throttling in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted payloads to specific integration API endpoints.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted payloads to specific integration API endpoints.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1477?
CVE-2025-1477 is classified as a denial of service vulnerability that can significantly impact service availability.
How do I fix CVE-2025-1477?
To mitigate CVE-2025-1477, upgrade GitLab CE/EE to version 18.0.6 or later, 18.1.4 or later, or 18.2.2 or later.
What versions are affected by CVE-2025-1477?
CVE-2025-1477 affects GitLab CE/EE versions from 8.14 to prior to 18.0.6, 18.1 to prior to 18.1.4, and 18.2 to prior to 18.2.2.
Who can exploit CVE-2025-1477?
CVE-2025-1477 can be exploited by unauthenticated users sending specially crafted payloads.
What impact does CVE-2025-1477 have?
The impact of CVE-2025-1477 is the potential for an induced denial of service condition on affected GitLab instances.