HIGH
CVE-2025-14513
CVSS
7.5
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially crafted JSON payloads in the protected branches API.
Summary dbcve.org
An unauthenticated attacker can send specially crafted JSON payloads to GitLab's protected branches API, causing a denial of service due to improper input validation. This affects all GitLab CE/EE versions from 16.11 through 18.9.1.
Mitigation
Upgrade GitLab to version 18.7.6, 18.8.6, 18.9.2 or later to receive the patch. As an interim measure, restrict network access to the protected branches API endpoint if possible.
Weakness (CWE)
CWE-1284
EPSS Score
0.48%
Probability of exploitation in next 30 days
40.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.