CVE-2025-3525

MEDIUM

GitLab 9.0-18.7.4, 18.8-18.8.4, 18.9-18.9.0 - Authenticated Denial of Service via CI Trigger API

Title source: llm
STIX 2.1

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have, under certain circumstances, allowed an authenticated user with certain access to cause Denial of Service by creating specially crafted CI triggers via the API.

References (3)

Core 3
Core References
Issue Tracking issue-tracking permissions-required
https://gitlab.com/gitlab-org/gitlab/-/issues/535662
Third Party Advisory technical-description exploit permissions-required
https://hackerone.com/reports/3045257

Scores

CVSS v3 6.5
EPSS 0.0031
EPSS Percentile 22.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (2)
gitlab/gitlab 18.9.0 (2 CPE variants)
gitlab/gitlab 9.0.0 - 18.7.5 (2 CPE variants)
Published Feb 25, 2026
Tracked Since Feb 26, 2026