Impact
GitLab’s GraphQL complexity calculation logic lacks limits on resource allocation, allowing an unauthenticated user to send crafted requests that trigger excessive CPU or memory usage, resulting in denial of service. The flaw is associated with CWE-770 and can bring a GitLab instance to a non-responsive state for legitimate users.
Affected Systems
All GitLab Community Edition and Enterprise Edition releases from version 18.4.6, inclusive, up to but not including the patched releases 19.1.8, 19.2.6, and 19.3.2 are affected. The recommended fix is to upgrade to any GitLab build 19.1.8, 19.2.6, 19.3.2, or later, which restores proper limits to the GraphQL complexity calculation.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of <1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the flaw allows unauthenticated GraphQL queries, an attacker could potentially deny service to system administrators or project maintainers, impacting repository service availability. The low EPSS suggests exploitation is unlikely, but the absence of a current patch still makes this a maintenance concern.
OpenCVE Enrichment