- Description
- GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.
- Source
- cve@gitlab.com
- NVD status
- Analyzed
- Products
- gitlab
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- cve@gitlab.com
- CWE-770
- Hype score
- Not currently trending
⚠️Vulnerabilidades corregidas en GitLab ❗CVE-2025-11340 ❗CVE-2025-10004 ➡️Más info: https://t.co/RC82OnN2Dr https://t.co/BdUoPyPIQt
@CERTpy
14 Oct 2025
87 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-10004 GraphQL Denial of Service Vulnerability in GitLab CE/EE Versions 13.12-18.4.2 https://t.co/9fgmEdEF2T
@VulmonFeeds
9 Oct 2025
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-11340, CVE-2025-10004, and other: Multiple vulns in GitLab, 4.3 - 7.7 rating❗️ In a recent bulletin, GitLab reported four vulns, including Missing Authorization, DoS, and Incorrect Authorization. Search at https://t.co/hv7QKSqxTR: 👉 Link: https://t.co/2ThlzQ9kRH
@Netlas_io
9 Oct 2025
437 Impressions
0 Retweets
3 Likes
2 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"matchCriteriaId": "BC727177-F9EF-438A-94B6-2BBCB78C4776",
"versionEndExcluding": "18.2.8",
"versionStartIncluding": "13.12.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "20F1A1DC-3585-492D-8FDF-71739290C905",
"versionEndExcluding": "18.2.8",
"versionStartIncluding": "13.12.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"matchCriteriaId": "536C1DFE-B81E-4E5E-A979-EBB8AEB62F4C",
"versionEndExcluding": "18.3.4",
"versionStartIncluding": "18.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "15A762DA-E645-404C-B831-A63171FF3EF2",
"versionEndExcluding": "18.3.4",
"versionStartIncluding": "18.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"matchCriteriaId": "A0684F06-FCCA-400A-AB87-BB9B9F906187",
"versionEndExcluding": "18.4.2",
"versionStartIncluding": "18.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "719CBD84-A5F7-4332-8C37-D68474A2FB70",
"versionEndExcluding": "18.4.2",
"versionStartIncluding": "18.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]