Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.5

CVE-2025-14157: GitLab: Authenticated User Can Crash GitLab with Large API Calls

CVE-2025-14157
Summary

GitLab has fixed a security issue that could allow a legitimate user to intentionally crash their own GitLab instance by sending a large amount of information through the API. This could cause the instance to become unresponsive. If you're running an affected version, please update to the latest version to ensure your instance remains stable.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
gitlab gitlab >= 6.3.0, < 18.4.6
>= 18.5.0, < 18.5.4
>= 18.6.0, < 18.6.2
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
Original title
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a Den...
Original description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a Denial of Service condition by sending crafted API calls with large content parameters.
nvd CVSS3.1 6.5
Vulnerability type
CWE-770 Allocation of Resources Without Limits
Published: 11 Dec 2025 · Updated: 15 Jun 2026 · First seen: 7 Mar 2026