GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Upgrade to version 18.2.8, 18.3.4 or 18.4.2
Workaround
No workaround given by the vendor.
References
History
Thu, 09 Oct 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 09 Oct 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs. | |
Title | Allocation of Resources Without Limits or Throttling in GitLab | |
First Time appeared |
Gitlab
Gitlab gitlab |
|
Weaknesses | CWE-770 | |
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gitlab
Gitlab gitlab |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-10-09T13:16:38.980Z
Reserved: 2025-09-04T18:33:25.673Z
Link: CVE-2025-10004

Updated: 2025-10-09T13:16:30.362Z

Status : Awaiting Analysis
Published: 2025-10-09T12:15:34.570
Modified: 2025-10-09T15:50:04.013
Link: CVE-2025-10004

No data.

No data.