← Back to CVE List
CVE-2025-13929NVD
Vulnerability Summary
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by issuing specially crafted requests to repository archive endpoints under certain conditions.
CVSS v3.1 Base Metrics — Score 7.5 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityHigh
Affected & Patched Versions
- Gitlab Gitlab >= 10.0.0 and < 18.7.6
- Gitlab Gitlab >= 18.8.0 and < 18.8.6
- Gitlab Gitlab >= 18.9.0 and < 18.9.2
- Gitlab Gitlab 18.7.6
- Gitlab Gitlab 18.8.6
- Gitlab Gitlab 18.9.2