CVE-2025-13078
GitLab vulnerability analysis and mitigation

Overview

CVE-2025-13078 is a Denial of Service (DoS) vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) caused by improper validation of specified quantity in input (CWE-1284) when processing webhook configuration inputs. It affects all GitLab CE/EE versions from 16.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1. The vulnerability was disclosed and patched on March 25, 2026, and was reported through GitLab's HackerOne bug bounty program by researcher 'lucky_luke'. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitLab Advisory, Red Hat CVE).

Technical details

The root cause is improper validation of specified quantity in input (CWE-1284) within GitLab's webhook configuration processing logic. An authenticated user can submit specially crafted webhook configuration inputs that trigger excessive resource consumption — such as CPU or memory exhaustion — on the GitLab server. The attack vector is network-based, requires low privileges (any authenticated user), and no user interaction, making it straightforward to trigger once an account is obtained. No public proof-of-concept or detailed technical write-up has been identified at this time (GitLab Advisory, Red Hat CVE).

Impact

Successful exploitation renders the GitLab instance unavailable to legitimate users by exhausting server resources through maliciously crafted webhook configuration inputs. The impact is limited to availability — there is no confidentiality or integrity impact, meaning attackers cannot access or modify data through this vulnerability alone. Self-managed GitLab installations are the primary risk; GitLab.com and GitLab Dedicated customers were patched automatically (GitLab Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The low privilege requirement (any authenticated user, no user interaction) does lower the barrier for exploitation if an attacker has valid credentials (Red Hat CVE).

Indicators of compromise

  • Logs: Repeated or unusual webhook configuration save/update requests in GitLab application logs from a single authenticated user account, particularly with abnormally large or complex input values.
  • System Resources: Sudden spikes in CPU or memory utilization on the GitLab server coinciding with webhook configuration activity, potentially visible in system monitoring tools.
  • Network: High-frequency API or web requests targeting webhook configuration endpoints (e.g., /hooks project or group settings endpoints) from a single source IP.
  • Application: GitLab service becoming unresponsive or returning 503 errors following webhook configuration changes.

Mitigation and workarounds

GitLab has released patched versions: 18.8.7, 18.9.3, and 18.10.1 for both CE and EE. All self-managed GitLab installations running affected versions (16.10 through 18.10.0) should upgrade immediately. As a temporary workaround, administrators can implement network-level access controls to restrict webhook configuration access to trusted administrators only, and monitor system resource utilization for unusual spikes. GitLab.com and GitLab Dedicated customers do not need to take action (GitLab Advisory).

Community reactions

The Belgium Centre for Cybersecurity (CCB) issued an advisory warning about multiple high-severity GitLab vulnerabilities in this patch release, recommending immediate patching. The vulnerability received standard coverage in vulnerability tracking databases and feeds. No notable independent researcher commentary or significant social media discussion specific to CVE-2025-13078 has been identified beyond routine CVE publication activity.

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19478CRITICAL9.4
  • GitLab logoGitLab
  • gitlab-rails-19.1
NoYesAug 17, 2026
CVE-2026-10053HIGH8.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 23, 2026
CVE-2026-19650HIGH7.1
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 17, 2026
CVE-2026-6821MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
NoYesAug 12, 2026
CVE-2026-4879MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management