Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to versions 18.6.4, 18.7.2, 18.8.2 or above.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 26 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
Thu, 22 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 22 Jan 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted requests with malformed authentication data. | |
| Title | Allocation of Resources Without Limits or Throttling in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-01-22T15:27:56.204Z
Reserved: 2025-12-02T21:04:23.292Z
Link: CVE-2025-13927
Updated: 2026-01-22T15:27:23.698Z
Status : Analyzed
Published: 2026-01-22T15:16:47.453
Modified: 2026-01-26T21:07:51.377
Link: CVE-2025-13927
No data.
OpenCVE Enrichment
No data.