CVE-2025-0673
GitLab vulnerability analysis and mitigation

Overview

CVE-2025-0673 is a denial-of-service vulnerability in GitLab CE/EE that allows an unauthenticated attacker to trigger an infinite redirect loop, potentially rendering the instance unresponsive. It affects all GitLab versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2 (both Community and Enterprise editions). The vulnerability was published on June 12, 2025, and assigned a CVSS v3.1 base score of 7.5 (High) (GitLab Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition / 'Infinite Loop'), where GitLab's redirect handling logic can be manipulated to enter a loop with no reachable termination condition. An unauthenticated remote attacker can exploit this over the network with low attack complexity and no privileges or user interaction required. The vulnerability was originally reported via HackerOne (report #2936949) and tracked in the GitLab issue tracker at gitlab.com/gitlab-org/gitlab/-/issues/514732 (GitLab Issue, Red Hat CVE).

Impact

Successful exploitation causes the GitLab server to enter an infinite redirect loop, consuming server resources and potentially making the instance fully unresponsive to legitimate users. The impact is limited to availability — there is no confidentiality or integrity impact, and the scope is unchanged (the attacker cannot leverage this to affect other systems). Organizations relying on GitLab for CI/CD pipelines, code hosting, or DevSecOps workflows could experience significant service disruption (GitLab Advisory, Red Hat CVE).

Exploitability

A proof-of-concept reference exists in the GitLab issue tracker (gitlab.com/gitlab-org/gitlab/-/issues/514732), added to exploit tracking on August 8, 2025. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.016% (0.000160), indicating a low probability of exploitation in the near term (GitLab Issue, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify internet-facing GitLab CE/EE instances running versions 17.7–17.10.7, 17.11.0–17.11.3, or 18.0.0–18.0.1 using tools like Shodan or Censys, or by checking the GitLab version endpoint (e.g., /api/v4/version if accessible).
  2. Craft redirect-triggering request: Send a specially crafted HTTP request to a GitLab endpoint that contains redirect logic, designed to cause the server to redirect back to itself or into a loop with no exit condition.
  3. Trigger the infinite loop: Submit the crafted request repeatedly or in a sustained manner; the server's redirect handler enters an unreachable exit condition (CWE-835), consuming CPU and memory resources.
  4. Achieve denial of service: The GitLab instance becomes unresponsive to legitimate users as server resources are exhausted by the looping redirect processing (GitLab Issue).

Indicators of compromise

  • Network: Unusual volume of HTTP redirect responses (3xx status codes) originating from the GitLab server to the same client or looping internally; repeated requests to the same GitLab endpoint from a single IP with no meaningful variation.
  • Logs: GitLab production logs (/var/log/gitlab/gitlab-rails/production.log) showing a high frequency of redirect chains or looping request patterns; web server (NGINX) access logs showing repeated 3xx responses to the same path.
  • Process/System: Elevated CPU or memory usage on the GitLab application server without a corresponding increase in legitimate user activity; Unicorn/Puma worker processes consuming abnormal resources.
  • Availability: GitLab web interface becoming slow or unresponsive; health check endpoints (/-/health, /-/readiness) returning errors or timing out.

Mitigation and workarounds

GitLab has released patched versions addressing this vulnerability: 17.10.8, 17.11.4, and 18.0.2. Administrators should upgrade to one of these versions immediately. As interim mitigations, deploying rate limiting and request validation at the network edge (e.g., via a WAF or reverse proxy) and monitoring for unusual redirect patterns can reduce exposure. GitLab.com (SaaS) was patched automatically and requires no user action (GitLab Advisory).

Community reactions

The vulnerability was covered alongside other high-severity GitLab issues patched in the same release cycle, including account takeover and missing authentication flaws, which drew broader community attention. BleepingComputer and SecurityOnline reported on the patch release, noting the combination of vulnerabilities addressed (BleepingComputer, SecurityOnline). CERT-EU issued a security advisory (2025-020) covering the GitLab patch release (CERT-EU Advisory). Community sentiment on social media (Mastodon, security forums) was focused primarily on the more severe account takeover CVEs in the same batch, with CVE-2025-0673 receiving moderate attention as a DoS-class issue.

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16553MEDIUM5.4
  • GitLab logoGitLab
  • gitlab
NoYesJul 29, 2026
CVE-2026-6336MEDIUM5.3
  • GitLab logoGitLab
  • gitlab-workhorse-ce-18.8
NoYesJul 29, 2026
CVE-2026-6267MEDIUM5.3
  • GitLab logoGitLab
  • gitlab-rails-ce-18.7
NoYesJul 29, 2026
CVE-2026-3093MEDIUM4.7
  • GitLab logoGitLab
  • gitlab-rails-ce-fips-18.6
NoYesJul 29, 2026
CVE-2026-4672MEDIUM4.3
  • GitLab logoGitLab
  • gitlab-rails-ce-18.6
NoYesJul 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management