CVE-2025-0639Allocation of Resources Without Limits or Throttling in Gitlab

Severity
7.5HIGHNVD
EPSS
0.3%
top 47.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 24

Description

An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages7 packages

CVEListV5gitlab/gitlab16.717.9.7+2
NVDgitlab/gitlab16.7.017.9.7+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-9963-8j6c-xr65: An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 162025-04-24
OSV
CVE-2025-0639: An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 162025-04-24

📋Vendor Advisories

3
GitLab
CVE-2025-0639: An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 be2025-04-24
Debian
CVE-2025-0639: gitlab - An issue has been discovered affecting service availability via issue preview in...2025
Microsoft
Kernel: potential deadlock on &net->sctp.addr_wq_lock leading to dos2024-01-09