CVE-2025-13078: Improper Validation of Specified Quantity in Input in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when processing certain webhook configuration inputs.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when processing certain webhook configuration inputs.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-13078?
The severity of CVE-2025-13078 is classified as a Denial of Service vulnerability.
How do I fix CVE-2025-13078?
To fix CVE-2025-13078, upgrade to GitLab versions 18.8.8, 18.9.4, or 18.10.2 or later.
Who is affected by CVE-2025-13078?
CVE-2025-13078 affects GitLab CE/EE versions prior to 18.8.8, 18.9.4, and 18.10.2.
What type of vulnerability is CVE-2025-13078?
CVE-2025-13078 is a Denial of Service vulnerability due to excessive resource consumption.
Can any user exploit CVE-2025-13078?
Yes, an authenticated user can exploit CVE-2025-13078 by inputting specific webhook configurations.