PT-2025-25286 · Gitlab · Gitlab Ce/Ee

CVE-2025-1478

·

Published

2025-06-11

·

Updated

2025-06-14

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 8.13 through 17.10.7 GitLab CE/EE versions 17.11 through 17.11.3 GitLab CE/EE versions 18.0 through 18.0.1
Description An issue has been discovered in GitLab CE/EE, where a lack of input validation in Board Names could be used to trigger a denial of service.
Recommendations For GitLab CE/EE versions 8.13 through 17.10.7, update to version 17.10.7 or later. For GitLab CE/EE versions 17.11 through 17.11.3, update to version 17.11.3 or later. For GitLab CE/EE versions 18.0 through 18.0.1, update to version 18.0.1 or later. As a temporary workaround, consider restricting access to Board Names to minimize the risk of exploitation.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06820
BIT-GITLAB-2025-1478
CVE-2025-1478

Affected Products

Gitlab Ce/Ee