GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content with nested formatting patterns.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Upgrade to versions 18.3.6, 18.4.4, 18.5.2 or above.
Workaround
No workaround given by the vendor.
References
History
Sat, 15 Nov 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content with nested formatting patterns. | |
| Title | Memory Allocation with Excessive Size Value in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-789 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-11-15T08:13:32.098Z
Reserved: 2025-11-10T20:34:10.628Z
Link: CVE-2025-12983
No data.
Status : Received
Published: 2025-11-15T09:15:41.950
Modified: 2025-11-15T09:15:41.950
Link: CVE-2025-12983
No data.
OpenCVE Enrichment
No data.