CVE-2025-1257Allocation of Resources Without Limits or Throttling in Gitlab

Severity
7.5HIGHNVD
EPSS
0.1%
top 68.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13
Latest updateJun 26

Description

An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab12.317.7.7+2
NVDgitlab/gitlab12.3.017.7.7+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-5mjv-86c4-mprj: An issue was discovered in GitLab EE affecting all versions starting with 122025-03-13

💥Exploits & PoCs

1
Exploit-DB
McAfee Agent 5.7.6 - Insecure Storage of Sensitive Information2025-06-26

📋Vendor Advisories

2
GitLab
CVE-2025-1257: An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulner2025-03-13
Debian
CVE-2025-1257: gitlab - An issue was discovered in GitLab EE affecting all versions starting with 12.3 b...2025