CVE-2025-7337: Allocation of Resources Without Limits or Throttling in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed an authenticated user with Developer-level access to cause a persistent denial of service affecting all users on a GitLab instance by uploading large files.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user with Developer-level access to cause a persistent denial of service affecting all users on a GitLab instance by uploading large files.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-7337?
CVE-2025-7337 has a high severity rating due to its potential for causing persistent denial of service for all users on affected GitLab instances.
How do I fix CVE-2025-7337?
To resolve CVE-2025-7337, upgrade your GitLab CE/EE to version 18.1.6, 18.2.6, or 18.3.2 or later.
Who is affected by CVE-2025-7337?
CVE-2025-7337 affects all GitLab CE/EE versions from 7.8 to before 18.1.6, from 18.2 to before 18.2.6, and from 18.3 to before 18.3.2.
What type of attack does CVE-2025-7337 facilitate?
CVE-2025-7337 allows an authenticated user with Developer-level access to execute actions that can lead to a persistent denial of service.
Can CVE-2025-7337 impact data integrity?
While CVE-2025-7337 primarily causes denial of service, it does not directly impact data integrity but disrupts service availability.