CVE-2025-2853: Allocation of Resources Without Limits or Throttling in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-2853?
CVE-2025-2853 is classified as a denial of service vulnerability affecting certain versions of GitLab CE/EE.
How do I fix CVE-2025-2853?
To fix CVE-2025-2853, upgrade to GitLab versions 17.10.7 or later, 17.11.3 or later, or 18.0.1 or later.
What versions of GitLab are affected by CVE-2025-2853?
CVE-2025-2853 affects GitLab CE/EE versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1.
Can CVE-2025-2853 be exploited by unauthenticated users?
No, CVE-2025-2853 requires an authenticated user to exploit the vulnerability.
What is the potential impact of CVE-2025-2853?
The potential impact of CVE-2025-2853 is a denial of service condition which can disrupt service availability.