GitLab CE/EE Denial-of-Service Vulnerability via Fogbugz Importer

Vulnerability

A denial-of-service vulnerability has been identified in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. The issue arises when maliciously crafted content is imported using the Fogbugz importer, leading to a denial-of-service condition.

Impact

Exploitation of this vulnerability causes a denial-of-service condition, disrupting normal application functionality.

Remediation

Users are advised to upgrade to GitLab versions 17.5.2, 17.4.4, or 17.3.7. Instructions for updating GitLab can be found on the GitLab update page.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.