VDB

CVE-2025-14157

CVE-2025-14157 PUBLISHED

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a Denial of Service condition by sending crafted API calls with large content parameters.

EPSS 0.08% · 23.0th percentile

Risk Scores

EPSS Score
0.08%
23.0th percentile

Affected Products

VendorProductVersions
Bitnamigitlab6.3.0, 18.5.0, 18.6.0
Bitnamigitlab18.5.0, 18.6.0, 6.3.0

Timeline

  • Dec 11, 2025 CVE Published
  • Dec 11, 2025 EPSS Score
  • Dec 11, 2025 PoC Published
  • Dec 11, 2025 PoC Published
  • Dec 15, 2025 EPSS Score
  • Dec 19, 2025 EPSS Score
  • Dec 23, 2025 EPSS Score
  • Dec 27, 2025 EPSS Score
  • Jan 1, 2026 EPSS Score
  • Jan 5, 2026 EPSS Score
  • Jan 9, 2026 EPSS Score
  • Jan 13, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›