VDB

CVE-2025-4097

CVE-2025-4097 PUBLISHED

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a denial of service condition by uploading specially crafted images.

EPSS 0.08% · 23.0th percentile

Risk Scores

EPSS Score
0.08%
23.0th percentile

Affected Products

VendorProductVersions
Bitnamigitlab11.10.0, 18.5.0, 18.6.0
Bitnamigitlab18.5.0, 18.6.0, 11.10.0

Timeline

  • Dec 11, 2025 CVE Published
  • Dec 11, 2025 EPSS Score
  • Dec 11, 2025 PoC Published
  • Dec 11, 2025 PoC Published
  • Dec 15, 2025 EPSS Score
  • Dec 19, 2025 EPSS Score
  • Dec 23, 2025 EPSS Score
  • Dec 27, 2025 EPSS Score
  • Jan 1, 2026 EPSS Score
  • Jan 5, 2026 EPSS Score
  • Jan 9, 2026 EPSS Score
  • Jan 13, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›