CVE Vulnerabilities

CVE-2025-13335

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jan 22, 2026 | Modified: Jan 26, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under certain circumstances could have allowed an authenticated user to create a denial of service condition by configuring malformed Wiki documents that bypass cycle detection.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab17.1.0 (including)18.6.4 (excluding)
GitlabGitlab18.7.0 (including)18.7.2 (excluding)
GitlabGitlab18.8.0 (including)18.8.2 (excluding)
GitlabUbuntuesm-apps/xenial*

References