PT-2025-25287 · Gitlab · Gitlab Ce/Ee

Published

2025-06-11

·

Updated

2025-06-14

·

CVE-2025-1516

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 8.7 through 17.10.8 GitLab CE/EE versions 17.11 through 17.11.4 GitLab CE/EE versions 18.0 through 18.0.2
Description An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper input validation in Tokens Names could be used to trigger a denial of service.
Recommendations For GitLab CE/EE versions 8.7 through 17.10.8, update to a version after 17.10.8 to resolve the issue. For GitLab CE/EE versions 17.11 through 17.11.4, update to a version after 17.11.4 to resolve the issue. For GitLab CE/EE versions 18.0 through 18.0.2, update to a version after 18.0.2 to resolve the issue. As a temporary workaround, consider restricting the use of Tokens Names to minimize the risk of exploitation.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-06826
BIT-GITLAB-2025-1516
CVE-2025-1516

Affected Products

Gitlab Ce/Ee