Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.
Metrics
Affected Vendors & Products
Fixes
Solution
Upgrade to version 18.4.1, 18.3.3, 18.2.7.
Workaround
No workaround given by the vendor.
References
History
Sat, 27 Sep 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption. | |
Title | Allocation of Resources Without Limits or Throttling in GitLab | |
First Time appeared |
Gitlab
Gitlab gitlab |
|
Weaknesses | CWE-770 | |
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gitlab
Gitlab gitlab |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-09-27T16:33:32.601Z
Reserved: 2025-07-22T01:32:55.510Z
Link: CVE-2025-8014

No data.

Status : Received
Published: 2025-09-27T17:15:33.987
Modified: 2025-09-27T17:15:33.987
Link: CVE-2025-8014

No data.

No data.