Junglewise Threat Intelligence

CVE-2025-14869: GitLab CE/EE denial of service via API endpoints

CVE-2025-14869 · Severity: high · CVSS 7.5 · Published 2026-05-14

Technologies: GitLab Community Edition, GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab, a platform used by organizations to manage and host software code, is affected by a vulnerability that allows unauthorized users to crash or slow down the service. By sending specifically designed data to certain parts of the system, an attacker can cause a denial of service, preventing legitimate employees from accessing their projects and disrupting software development workflows. This issue has been resolved in the latest security updates.

Technical details

A denial of service (DoS) vulnerability exists in GitLab CE/EE due to improper validation of specified quantities in input (CWE-1284). An unauthenticated remote attacker can exploit this by sending specially crafted payloads to vulnerable API endpoints. Successful exploitation allows the attacker to exhaust system resources or crash the service, leading to a loss of availability. The issue affects versions 18.5 through 18.11.2 and has been patched in versions 18.9.7, 18.10.6, and 18.11.3.

Affected products

  • GitLab GitLab Community Edition (CE) / Enterprise Edition (EE) 18.5 to < 18.9.7, 18.10 to < 18.10.6, 18.11 to < 18.11.3

Timeline

  • 2026-05-13: patched: GitLab released versions 18.9.7, 18.10.6, and 18.11.3 to address the issue.
  • 2026-05-14: disclosed: Public disclosure of CVE-2025-14869.

References

Related threats