First published: Thu Apr 10 2025(Updated: )
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A denial of service could occur upon injecting oversized payloads into CI pipeline exports.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Community Edition | <=17.8.7<17.9.6<17.10.4 |
Upgrade to version 17.10.4, 17.9.6 or 17.8.7
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1677 has a severity rating of Medium as it leads to a Denial of Service (DoS) affecting GitLab CE/EE.
To fix CVE-2025-1677, upgrade your GitLab CE/EE instance to version 17.9.6 or 17.10.4 or later.
CVE-2025-1677 affects GitLab CE/EE versions up to 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4.
CVE-2025-1677 enables a Denial of Service (DoS) attack through the injection of oversized payloads into CI pipeline exports.
Currently, there is no published workaround for CVE-2025-1677; updating to a fixed version is the recommended solution.