GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses.
Metrics
Affected Vendors & Products
References
History
Thu, 09 Oct 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 09 Oct 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses. | |
Title | Allocation of Resources Without Limits or Throttling in GitLab | |
First Time appeared |
Gitlab
Gitlab gitlab |
|
Weaknesses | CWE-770 | |
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gitlab
Gitlab gitlab |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-10-09T13:48:56.561Z
Reserved: 2025-03-28T17:02:01.256Z
Link: CVE-2025-2934

Updated: 2025-10-09T13:48:52.706Z

Status : Received
Published: 2025-10-09T12:15:35.477
Modified: 2025-10-09T12:15:35.477
Link: CVE-2025-2934

No data.

No data.