CVE-2025-1677: GitLab

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A denial of service could occur upon injecting oversized payloads into CI pipeline exports.

Affected products

  • GitLab GitLab: up to and including 17.8.7; from 17.9.0, before 17.9.6 (fixed in 17.9.6); from 17.10.0, before 17.10.4 (fixed in 17.10.4)

Published 2025-04-10. Last modified 2026-06-17.