CVE-2025-2934: Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue impacting an upstream Ruby Core library that could have allowed an authenticated user to create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses. This issue was reported to Ruby Core maintainers on July 17, 2025.Impacted Versions: GitLab CE/EE: all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2CVSS: 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
Other sources
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses.
— MITRE
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-2934?
CVE-2025-2934 has been classified as a denial of service vulnerability.
How do I fix CVE-2025-2934?
To remediate CVE-2025-2934, upgrade GitLab CE/EE to version 18.2.8, 18.3.4, or 18.4.2 or later.
Which versions of GitLab are affected by CVE-2025-2934?
CVE-2025-2934 affects GitLab CE/EE versions from 5.2 to just before 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2.
Can an unauthenticated user exploit CVE-2025-2934?
No, CVE-2025-2934 requires an authenticated attacker to exploit the vulnerability.
What type of attack can CVE-2025-2934 facilitate?
CVE-2025-2934 can facilitate a denial of service condition through malicious webhook endpoints.