
CVE-2024-7803 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2024-7803
23 May 2025 — An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause DoS. • https://gitlab.com/gitlab-org/gitlab/-/issues/479168 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2024-9163 – User Interface (UI) Misrepresentation of Critical Information in GitLab
https://notcve.org/view.php?id=CVE-2024-9163
23 May 2025 — A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs. • https://gitlab.com/gitlab-org/gitlab/-/issues/493942 • CWE-451: User Interface (UI) Misrepresentation of Critical Information •

CVE-2024-12093 – Improper Validation of Consistency within Input in GitLab
https://notcve.org/view.php?id=CVE-2024-12093
22 May 2025 — An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions. • https://gitlab.com/gitlab-org/gitlab/-/issues/507445 • CWE-1288: Improper Validation of Consistency within Input •

CVE-2025-0605 – Weak Authentication in GitLab
https://notcve.org/view.php?id=CVE-2025-0605
22 May 2025 — An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements. • https://gitlab.com/gitlab-org/gitlab/-/issues/514204 • CWE-1390: Weak Authentication •

CVE-2025-0679 – Exposure of Private Personal Information to an Unauthorized Actor in GitLab
https://notcve.org/view.php?id=CVE-2025-0679
22 May 2025 — An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured. • https://gitlab.com/gitlab-org/gitlab/-/issues/514751 • CWE-359: Exposure of Private Personal Information to an Unauthorized Actor •

CVE-2025-0993 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2025-0993
22 May 2025 — An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources. • https://gitlab.com/gitlab-org/gitlab/-/issues/516927 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2025-1110 – Insufficient Granularity of Access Control in GitLab
https://notcve.org/view.php?id=CVE-2025-1110
22 May 2025 — An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query. • https://gitlab.com/gitlab-org/gitlab/-/issues/517693 • CWE-1220: Insufficient Granularity of Access Control •

CVE-2025-2853 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2025-2853
22 May 2025 — An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition. • https://gitlab.com/gitlab-org/gitlab/-/issues/527218 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2025-3111 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2025-3111
22 May 2025 — An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service.. • https://gitlab.com/gitlab-org/gitlab/-/issues/533313 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2025-4979 – Insufficient Granularity of Access Control in GitLab
https://notcve.org/view.php?id=CVE-2025-4979
22 May 2025 — An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response. • https://gitlab.com/gitlab-org/gitlab/-/issues/524455 • CWE-1220: Insufficient Granularity of Access Control •