Impact
The vulnerability allows an authenticated GitLab user to trigger excessive memory usage, which can bring the system to a halt, rendering services unavailable. It results from improper input validation in code paths accessed by authenticated users, leading to a denial of service condition. The weakness aligns with CWE‑770, indicating insufficient limits on resource allocation.
Affected Systems
All GitLab Community Edition and Enterprise Edition installations from version 8.3 up to just before 18.9.7, 18.10.6, and 18.11.3 are affected. Upgrading to GitLab 18.9.7, 18.10.6, 18.11.3, or any later release removes the issue.
Risk and Exploitability
The CVSS score of 6.5 reflects a medium-severity impact. No EPSS value is available, so the likelihood of exploitation cannot be quantified from the current dataset. The vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation at release time. The attack vector is inferred to be through authenticated access to GitLab, since the description mentions authenticated users. Successful exploitation would enable an attacker to consume server memory until the system becomes unresponsive, potentially affecting all users on that instance.
OpenCVE Enrichment