CVE-2025-3601Allocation of Resources Without Limits or Throttling in Gitlab

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 74.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 27

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have could have allowed an authenticated user to cause a Denial of Service (DoS) condition by submitting URLs that generate excessively large responses.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab8.1518.1.5+2
NVDgitlab/gitlab8.15.018.1.5+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-v8g6-hvf8-9cwq: An issue has been discovered in GitLab CE/EE affecting all versions from 82025-08-27

📋Vendor Advisories

2
GitLab
CVE-2025-3601: An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could hav2025-08-27
Debian
CVE-2025-3601: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 be...2025