CVE-2025-1257: Allocation of Resources Without Limits or Throttling in GitLab
An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1257?
CVE-2025-1257 is classified as a denial of service vulnerability affecting certain versions of GitLab EE.
How do I fix CVE-2025-1257?
To resolve CVE-2025-1257, upgrade GitLab EE to version 17.8.5 or later, or 17.9.2 or later.
What versions of GitLab EE are affected by CVE-2025-1257?
CVE-2025-1257 affects GitLab EE versions from 12.3 up to, but not including, 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2.
What kind of attack can CVE-2025-1257 facilitate?
CVE-2025-1257 can allow an attacker to cause a denial of service condition by manipulating specific API inputs.
Where can I find more information about CVE-2025-1257?
More information about CVE-2025-1257 can be found in the GitLab issue tracker and related reports.