An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics.
2025-01-09T06:15:15.390
2025-08-05T15:21:23.017
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | gitlab | gitlab | < 17.5.5 | Yes |
| Application | gitlab | gitlab | < 17.5.5 | Yes |
| Application | gitlab | gitlab | < 17.6.3 | Yes |
| Application | gitlab | gitlab | < 17.6.3 | Yes |
| Application | gitlab | gitlab | < 17.7.1 | Yes |
| Application | gitlab | gitlab | < 17.7.1 | Yes |