
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-0673 is a denial-of-service vulnerability in GitLab CE/EE that allows an unauthenticated attacker to trigger an infinite redirect loop, potentially rendering the instance unresponsive. It affects all GitLab versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2 (both Community and Enterprise editions). The vulnerability was published on June 12, 2025, and assigned a CVSS v3.1 base score of 7.5 (High) (GitLab Advisory, Red Hat CVE).
The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition / 'Infinite Loop'), where GitLab's redirect handling logic can be manipulated to enter a loop with no reachable termination condition. An unauthenticated remote attacker can exploit this over the network with low attack complexity and no privileges or user interaction required. The vulnerability was originally reported via HackerOne (report #2936949) and tracked in the GitLab issue tracker at gitlab.com/gitlab-org/gitlab/-/issues/514732 (GitLab Issue, Red Hat CVE).
Successful exploitation causes the GitLab server to enter an infinite redirect loop, consuming server resources and potentially making the instance fully unresponsive to legitimate users. The impact is limited to availability — there is no confidentiality or integrity impact, and the scope is unchanged (the attacker cannot leverage this to affect other systems). Organizations relying on GitLab for CI/CD pipelines, code hosting, or DevSecOps workflows could experience significant service disruption (GitLab Advisory, Red Hat CVE).
A proof-of-concept reference exists in the GitLab issue tracker (gitlab.com/gitlab-org/gitlab/-/issues/514732), added to exploit tracking on August 8, 2025. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.016% (0.000160), indicating a low probability of exploitation in the near term (GitLab Issue, Red Hat CVE).
/api/v4/version if accessible)./var/log/gitlab/gitlab-rails/production.log) showing a high frequency of redirect chains or looping request patterns; web server (NGINX) access logs showing repeated 3xx responses to the same path./-/health, /-/readiness) returning errors or timing out.GitLab has released patched versions addressing this vulnerability: 17.10.8, 17.11.4, and 18.0.2. Administrators should upgrade to one of these versions immediately. As interim mitigations, deploying rate limiting and request validation at the network edge (e.g., via a WAF or reverse proxy) and monitoring for unusual redirect patterns can reduce exposure. GitLab.com (SaaS) was patched automatically and requires no user action (GitLab Advisory).
The vulnerability was covered alongside other high-severity GitLab issues patched in the same release cycle, including account takeover and missing authentication flaws, which drew broader community attention. BleepingComputer and SecurityOnline reported on the patch release, noting the combination of vulnerabilities addressed (BleepingComputer, SecurityOnline). CERT-EU issued a security advisory (2025-020) covering the GitLab patch release (CERT-EU Advisory). Community sentiment on social media (Mastodon, security forums) was focused primarily on the more severe account takeover CVEs in the same batch, with CVE-2025-0673 receiving moderate attention as a DoS-class issue.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."