CVE-2025-3111: Allocation of Resources Without Limits or Throttling in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service. This is a medium severity issue (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, 6.5). It is now mitigated in the latest release and is assigned CVE-2025-3111.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-3111?
CVE-2025-3111 has a high severity rating due to its potential to cause denial of service.
How do I fix CVE-2025-3111?
To fix CVE-2025-3111, upgrade to GitLab versions 17.10.7, 17.11.3, or 18.0.1 or later.
Which versions are affected by CVE-2025-3111?
CVE-2025-3111 affects GitLab CE/EE versions from 10.2 up to 17.10.6, 17.11 up to 17.11.2, and 18.0 up to 18.0.
Who can exploit CVE-2025-3111?
CVE-2025-3111 can be exploited by authenticated users of the affected GitLab installations.
What vulnerabilities does CVE-2025-3111 address?
CVE-2025-3111 addresses a lack of input validation in the Kubernetes integration that leads to denial of service.