HIGH
CVE-2025-0639
CVSS
7.5
Description
An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.
Summary dbcve.org
A service availability vulnerability exists in GitLab CE/EE's issue preview functionality. The flaw allows attackers to potentially disrupt service availability via the issue preview feature in affected versions.
Mitigation
Upgrade GitLab to version 17.9.7, 17.10.5, or 17.11.1 or later. Alternatively, disable or restrict issue preview functionality until patching can be completed.
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
0.45%
Probability of exploitation in next 30 days
38.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.