HIGH
CVE-2025-1478
CVSS
7.5
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in Board Names could be used to trigger a denial of service.
Summary dbcve.org
A denial of service vulnerability in GitLab CE/EE stems from insufficient input validation on Board Names. Attackers can exploit this to cause service disruption by submitting specially crafted board names. The issue affects all versions from 8.13 through the vulnerable ranges prior to 17.10.7, 17.11.3, and 18.0.1.
Mitigation
Update GitLab to version 17.10.7, 17.11.3, 18.0.1 or later to patch this vulnerability. As a compensating control, restrict board creation permissions to trusted users until the update is applied.
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
0.41%
Probability of exploitation in next 30 days
35.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.