CVE-2025-4097: Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a denial of service condition by uploading specially crafted images.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to cause a denial of service condition by uploading specially crafted images.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4097?
CVE-2025-4097 is classified as a denial of service vulnerability affecting GitLab.
How do I fix CVE-2025-4097?
To remediate CVE-2025-4097, upgrade to GitLab versions 18.4.7, 18.5.5, or 18.6.3.
Who is affected by CVE-2025-4097?
CVE-2025-4097 affects authenticated GitLab users on versions prior to 18.4.6, 18.5.4, and 18.6.2.
What type of attack does CVE-2025-4097 facilitate?
CVE-2025-4097 allows an authenticated user to cause a denial of service condition by uploading specially crafted images.
When was CVE-2025-4097 disclosed?
CVE-2025-4097 was disclosed in December 2025 as part of a GitLab patch release.