CVE-2025-1677: GitLab
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A denial of service could occur upon injecting oversized payloads into CI pipeline exports.
Affected products
- GitLab GitLab: up to and including 17.8.7; from 17.9.0, before 17.9.6 (fixed in 17.9.6); from 17.10.0, before 17.10.4 (fixed in 17.10.4)
Published 2025-04-10. Last modified 2026-06-17.