CVE-2025-5996: Allocation of Resources Without Limits or Throttling in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 2.1.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. A lack of input validation in HTTP responses could allow an authenticated user to cause denial of service.
Other sources
GitLab has remediated an issue that could have allowed a successful attacker to deny access to legitimate users of the targeted system by integrating a malicious third-party component into a GitLab project.Impacted versions GitLab CE/EE: versions from 2.1.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-5996?
CVE-2025-5996 has a high severity rating due to its potential to cause denial of service through input validation issues.
How do I fix CVE-2025-5996?
To fix CVE-2025-5996, upgrade GitLab CE/EE to versions 17.10.8, 17.11.4, or 18.0.2 and above.
Who is affected by CVE-2025-5996?
CVE-2025-5996 affects all GitLab CE/EE versions from 2.1.0 up to but not including 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2.
What type of vulnerability is CVE-2025-5996?
CVE-2025-5996 is classified as an input validation vulnerability that can lead to denial of service.
Can CVE-2025-5996 be exploited by an unauthenticated user?
No, CVE-2025-5996 requires an authenticated user to exploit the denial of service vulnerability.