CVE-2025-12983: Memory Allocation with Excessive Size Value in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content with nested formatting patterns.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to cause a denial of service condition by submitting specially crafted markdown content with nested formatting patterns.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-12983?
CVE-2025-12983 is classified as a moderate severity vulnerability due to its potential to cause denial of service conditions.
How do I fix CVE-2025-12983?
To remediate CVE-2025-12983, upgrade to GitLab versions 18.3.6, 18.4.4, or 18.5.2 or later.
Which versions of GitLab are affected by CVE-2025-12983?
CVE-2025-12983 affects GitLab CE/EE versions from 16.9 to just before 18.3.6, 18.4 to just before 18.4.4, and 18.5 to just before 18.5.2.
Can an unauthenticated user exploit CVE-2025-12983?
No, CVE-2025-12983 requires authentication for exploitation, as it involves submitting specially crafted markdown content.
What type of attack does CVE-2025-12983 involve?
CVE-2025-12983 involves a denial of service attack that can be executed through specially crafted markdown content.