
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13078 is a Denial of Service (DoS) vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) caused by improper validation of specified quantity in input (CWE-1284) when processing webhook configuration inputs. It affects all GitLab CE/EE versions from 16.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1. The vulnerability was disclosed and patched on March 25, 2026, and was reported through GitLab's HackerOne bug bounty program by researcher 'lucky_luke'. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitLab Advisory, Red Hat CVE).
The root cause is improper validation of specified quantity in input (CWE-1284) within GitLab's webhook configuration processing logic. An authenticated user can submit specially crafted webhook configuration inputs that trigger excessive resource consumption — such as CPU or memory exhaustion — on the GitLab server. The attack vector is network-based, requires low privileges (any authenticated user), and no user interaction, making it straightforward to trigger once an account is obtained. No public proof-of-concept or detailed technical write-up has been identified at this time (GitLab Advisory, Red Hat CVE).
Successful exploitation renders the GitLab instance unavailable to legitimate users by exhausting server resources through maliciously crafted webhook configuration inputs. The impact is limited to availability — there is no confidentiality or integrity impact, meaning attackers cannot access or modify data through this vulnerability alone. Self-managed GitLab installations are the primary risk; GitLab.com and GitLab Dedicated customers were patched automatically (GitLab Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The low privilege requirement (any authenticated user, no user interaction) does lower the barrier for exploitation if an attacker has valid credentials (Red Hat CVE).
/hooks project or group settings endpoints) from a single source IP.GitLab has released patched versions: 18.8.7, 18.9.3, and 18.10.1 for both CE and EE. All self-managed GitLab installations running affected versions (16.10 through 18.10.0) should upgrade immediately. As a temporary workaround, administrators can implement network-level access controls to restrict webhook configuration access to trusted administrators only, and monitor system resource utilization for unusual spikes. GitLab.com and GitLab Dedicated customers do not need to take action (GitLab Advisory).
The Belgium Centre for Cybersecurity (CCB) issued an advisory warning about multiple high-severity GitLab vulnerabilities in this patch release, recommending immediate patching. The vulnerability received standard coverage in vulnerability tracking databases and feeds. No notable independent researcher commentary or significant social media discussion specific to CVE-2025-13078 has been identified beyond routine CVE publication activity.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."