VDB
CVE-2025-12571
CVE-2025-12571
PUBLISHED
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an unauthenticated user to cause a Denial of Service condition by sending specifically crafted requests containing malicious JSON payloads.
EPSS 0.11% · 29.4th percentile
Risk Scores
EPSS Score
0.11%
29.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 17.10.0, 18.6.0, 18.5.0 |
| Bitnami | gitlab | 17.10.0, 18.5.0, 18.6.0 |
Timeline
- Jan 21, 1970 Security Advisory
- Nov 26, 2025 Coalition ESS Score
- Nov 26, 2025 CVE Published
- Nov 26, 2025 PoC Published
- Nov 27, 2025 EPSS Score
- Nov 27, 2025 PoC Published
- Nov 29, 2025 PoC Published
- Nov 30, 2025 Coalition ESS Score
- Dec 2, 2025 EPSS Score
- Dec 5, 2025 Coalition ESS Score
- Dec 6, 2025 EPSS Score
- Dec 11, 2025 EPSS Score