
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-4097 is a denial of service vulnerability in GitLab CE/EE caused by improper handling of specially crafted images during ExifTool processing. It affects all versions from 11.10 before 18.4.6, versions 18.5 before 18.5.4, and versions 18.6 before 18.6.2. The vulnerability was disclosed on December 10–11, 2025, when GitLab released patched versions. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitLab Advisory, Red Hat CVE).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), meaning GitLab fails to adequately constrain resource consumption when processing image metadata via ExifTool. An authenticated attacker can upload a specially crafted image file that causes ExifTool — the library GitLab uses to extract image metadata — to consume excessive resources, leading to a denial of service condition. Exploitation requires only low-privileged authenticated access and no user interaction, making it straightforward for any registered user to trigger. No public proof-of-concept code has been identified at this time (GitLab Advisory, Red Hat CVE).
Successful exploitation results in a denial of service condition affecting the availability of the GitLab instance, with no impact on confidentiality or integrity. An authenticated attacker could repeatedly upload malicious images to exhaust server resources, potentially rendering the GitLab service unavailable to all users. This is particularly impactful for self-managed GitLab deployments hosting critical development infrastructure, as prolonged unavailability could disrupt CI/CD pipelines and code collaboration workflows (GitLab Advisory).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-4097. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.032%, indicating a low probability of exploitation in the near term. Exploitation requires authenticated access, which limits the attacker pool but does not eliminate risk in environments with open registration (Red Hat CVE).
production.log); ExifTool-related errors or timeouts in GitLab worker logs (sidekiq.log)./uploads, issue/MR comment endpoints) from a single source IP.GitLab released patched versions on December 10, 2025: 18.6.2, 18.5.4, and 18.4.6 for both Community Edition and Enterprise Edition. All self-managed GitLab installations running affected versions (11.10 through 18.6.1) should upgrade to one of these versions immediately. GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take action. No configuration-based workaround has been published; upgrading is the only recommended remediation (GitLab Advisory).
The vulnerability was covered by cybersecurity news outlets including Cybersecurity News and Cybernoz, which reported on the broader December 2025 GitLab patch release addressing multiple XSS and DoS vulnerabilities. The Belgian Centre for Cybersecurity (CCB) issued an advisory warning about high-severity vulnerabilities in the same GitLab patch batch. Community reaction has been relatively muted given the medium severity rating and the requirement for authenticated access, with no notable researcher commentary or significant social media discussion specific to CVE-2025-4097 (Cybersecurity News, CCB Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."