CVE-2025-1257 — Allocation of Resources Without Limits or Throttling in Gitlab
Severity
7.5HIGHNVD
EPSS
0.1%
top 68.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 13
Latest updateJun 26
Description
An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages5 packages
🔴Vulnerability Details
1GHSA▶
GHSA-5mjv-86c4-mprj: An issue was discovered in GitLab EE affecting all versions starting with 12↗2025-03-13
💥Exploits & PoCs
1📋Vendor Advisories
2GitLab▶
CVE-2025-1257: An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulner↗2025-03-13
Debian▶
CVE-2025-1257: gitlab - An issue was discovered in GitLab EE affecting all versions starting with 12.3 b...↗2025