← Back to CVE List
CVE-2025-14513NVD
Vulnerability Summary
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially crafted JSON payloads in the protected branches API.
CVSS v3.1 Base Metrics — Score 7.5 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityHigh
Affected & Patched Versions
- Gitlab Gitlab >= 16.11.0 and < 18.7.6
- Gitlab Gitlab >= 18.8.0 and < 18.8.6
- Gitlab Gitlab >= 18.9.0 and < 18.9.2
- Gitlab Gitlab 18.7.6
- Gitlab Gitlab 18.8.6
- Gitlab Gitlab 18.9.2