{"id":"CVE-2025-2934","summary":"Allocation of Resources Without Limits or Throttling in GitLab","details":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses.","aliases":["BIT-gitlab-2025-2934"],"modified":"2026-09-11T03:48:19.342696450Z","published":"2025-10-09T11:33:43.956Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/2xxx/CVE-2025-2934.json","cna_assigner":"GitLab","cwe_ids":["CWE-770"]},"references":[{"type":"WEB","url":"https://about.gitlab.com/releases/2025/10/08/patch-release-gitlab-18-4-2-released/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/2xxx/CVE-2025-2934.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2934"},{"type":"REPORT","url":"https://gitlab.com/gitlab-org/gitlab/-/issues/528979"},{"type":"REPORT","url":"https://hackerone.com/reports/3058791"},{"type":"PACKAGE","url":"git://git@gitlab.com:gitlab-org/gitlab.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/gitlab-org/gitlab","events":[{"introduced":"6956c797611500ab731808e849ad4c71a3640c34"},{"fixed":"064b7e40da0b30ea250d4486cc3f08c5328a4165"},{"introduced":"94282cd9b41643ecd8a82da6cf46834cd9609afe"},{"fixed":"5f66dfbe719f204a376af73ef283481886cf08d2"},{"introduced":"9255f56b45844196bb7657a9f1fde6aa65a5d08d"},{"fixed":"527e88bdddb02340974a968de1ddcfa4ed7735e5"}],"database_specific":{"extracted_events":[{"introduced":"5.2"},{"fixed":"18.2.8"},{"introduced":"18.3"},{"fixed":"18.3.4"},{"introduced":"18.4"},{"fixed":"18.4.2"}],"source":"AFFECTED_FIELD"}}],"versions":["v18.4.0-ee","v18.3.0-ee","v18.2.4-ee","v18.2.3-ee","v18.2.0-ee","v18.2.0-rc43-ee","v18.2.0-rc42-ee","11-10-0cfa69752d8-74ffd66ae-ee","11-10-0cfa69752d8-0d9531c80-ee","11-10-119f9509d50-6d7537235-ee","v7.3.0-ee","v7.3.0.rc1-ee","v7.2.0.rc5-ee","v7.2.0.rc4-ee","v7.2.0.rc3-ee","v7.2.0.rc2-ee","v7.2.0.rc1-ee","v7.1.0-ee","v7.1.0.rc1-ee","v7.0.0-ee","v6.8.0-ee","v6.7.0-ee","v6.7.0.rc1-ee","v6.6.0-ee","v6.5.0-ee","v6.4.0-ee","v6.3.1-ee","v6.3.0-ee","v6.1.0-ee","v6.0.0-ee","v6.0.0-ee.rc1","v6.0.0-ee.beta","v5.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-2934.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"}]}