HIGH
CVE-2025-1516
CVSS
7.5
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper input validation in Tokens Names could be used to trigger a denial of service.
Summary dbcve.org
Improper input validation in GitLab's Token Names feature allows attackers to trigger a denial of service. The vulnerability exists in all versions from 8.7 through the unpatched versions of 17.10.x, 17.11.x, and 18.0.x.
Mitigation
Upgrade GitLab to version 17.10.8, 17.11.4, 18.0.2 or later to patch the input validation vulnerability in Token Names.
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
0.41%
Probability of exploitation in next 30 days
35.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.