CVE-2025-6016: Denial of Service issue in notes endpoint impacts GitLab CE/EE
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service due to insufficient resource allocation limits when retrieving notes under certain conditions.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to cause denial of service due to insufficient resource allocation limits when retrieving notes under certain conditions.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-6016?
CVE-2025-6016 is classified as a Denial of Service vulnerability affecting specific versions of GitLab CE and EE.
How do I fix CVE-2025-6016?
To remediate CVE-2025-6016, upgrade your GitLab CE or EE to versions 18.9.6, 18.10.4, or 18.11.1.
Who is affected by CVE-2025-6016?
CVE-2025-6016 affects all authenticated users of GitLab CE and EE versions from 9.2 up to prior releases of 18.9.6, 18.10.4, and 18.11.1.
What versions of GitLab are impacted by CVE-2025-6016?
CVE-2025-6016 impacts GitLab CE and EE versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1.
Is there a patch available for CVE-2025-6016?
Yes, patches for CVE-2025-6016 are included in the releases 18.9.6, 18.10.4, and 18.11.1 of GitLab.