PT-2025-25286 · Gitlab · Gitlab Ce/Ee

Published

2025-06-11

·

Updated

2025-06-14

·

CVE-2025-1478

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 8.13 through 17.10.7 GitLab CE/EE versions 17.11 through 17.11.3 GitLab CE/EE versions 18.0 through 18.0.1
Description An issue has been discovered in GitLab CE/EE, where a lack of input validation in Board Names could be used to trigger a denial of service.
Recommendations For GitLab CE/EE versions 8.13 through 17.10.7, update to version 17.10.7 or later. For GitLab CE/EE versions 17.11 through 17.11.3, update to version 17.11.3 or later. For GitLab CE/EE versions 18.0 through 18.0.1, update to version 18.0.1 or later. As a temporary workaround, consider restricting access to Board Names to minimize the risk of exploitation.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-06820
BIT-GITLAB-2025-1478
CVE-2025-1478

Affected Products

Gitlab Ce/Ee