CVE-2025-1072: Allocation of Resources Without Limits or Throttling in GitLab
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. A denial of service could occur upon importing maliciously crafted content using the Fogbugz importer.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1072?
CVE-2025-1072 is classified as a Denial of Service (DoS) vulnerability.
How do I fix CVE-2025-1072?
To fix CVE-2025-1072, upgrade to GitLab version 17.3.7 or later, 17.4.4 or later, or 17.5.2 or later.
What versions of GitLab are affected by CVE-2025-1072?
GitLab versions from 7.14.1 to 17.3.6, 17.4 to 17.4.3, and 17.5 to 17.5.1 are affected by CVE-2025-1072.
What type of vulnerability is CVE-2025-1072?
CVE-2025-1072 is a Denial of Service (DoS) vulnerability related to importing malicious content.
Can CVE-2025-1072 be exploited by regular users?
Yes, CVE-2025-1072 can be exploited if a user imports maliciously crafted content using the Fogbugz importer.