Executive brief
GitLab, a platform used by organizations to manage and host software code, is affected by a vulnerability that allows unauthorized users to crash or slow down the service. By sending specifically designed data to certain parts of the system, an attacker can cause a denial of service, preventing legitimate employees from accessing their projects and disrupting software development workflows. This issue has been resolved in the latest security updates.
Technical details
A denial of service (DoS) vulnerability exists in GitLab CE/EE due to improper validation of specified quantities in input (CWE-1284). An unauthenticated remote attacker can exploit this by sending specially crafted payloads to vulnerable API endpoints. Successful exploitation allows the attacker to exhaust system resources or crash the service, leading to a loss of availability. The issue affects versions 18.5 through 18.11.2 and has been patched in versions 18.9.7, 18.10.6, and 18.11.3.
Affected products
- GitLab GitLab Community Edition (CE) / Enterprise Edition (EE) 18.5 to < 18.9.7, 18.10 to < 18.10.6, 18.11 to < 18.11.3
Timeline
- 2026-05-13: patched: GitLab released versions 18.9.7, 18.10.6, and 18.11.3 to address the issue.
- 2026-05-14: disclosed: Public disclosure of CVE-2025-14869.