Denial of Service Vulnerability in GitLab CE/EE Affects Multiple Versions
CVE-2025-4097
6.5MEDIUM
What is CVE-2025-4097?
A vulnerability exists in GitLab CE/EE that allows an authenticated user to trigger a denial of service condition by uploading specially crafted images. This issue affects a range of versions from 11.10 up to 18.6.2, potentially disrupting services and user access. It is essential for users to ensure they are on the patched versions to safeguard against this threat.
Affected Version(s)
GitLab 11.10 < 18.4.6
GitLab 18.5 < 18.5.4
GitLab 18.6 < 18.6.2