- Description
- Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.
- Source
- cve@gitlab.com
- NVD status
- Analyzed
- Products
- gitlab
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- cve@gitlab.com
- CWE-770
- Hype score
- Not currently trending
⚠️Vulnerabilidades corregidas en GitLab ❗CVE-2025-10858 ❗CVE-2025-8014 ➡️Más info: https://t.co/bpGfFQ9iwO https://t.co/r7Y8O87TpU
@CERTpy
30 Sept 2025
145 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
GitLab GraphQL DoS: Patch Now A new DoS vuln (CVE-2025-8014) in GitLab's GraphQL API can take your service offline fast. Update to the latest version to stay safe. For more details, read ZeroPath's blog on this vuln. #AppSec #GitLab #InfoSec https://t.co/ppHQEme62P
@ZeroPathLabs
27 Sept 2025
81 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-8014 Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows un… https://t.co/8VWBwuNjlY
@CVEnew
27 Sept 2025
449 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"matchCriteriaId": "93BFA3A3-74FF-4A3C-A852-47222A68EEB4",
"versionEndExcluding": "18.2.7",
"versionStartIncluding": "11.10.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "318545D2-1C74-4698-8414-212C8D6BA4BF",
"versionEndExcluding": "18.2.7",
"versionStartIncluding": "11.10.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"matchCriteriaId": "75F843E1-B1EB-44F7-9966-9874F512A487",
"versionEndExcluding": "18.3.3",
"versionStartIncluding": "18.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "FEDB2960-F05D-4510-ACD3-05F16E621C6B",
"versionEndExcluding": "18.3.3",
"versionStartIncluding": "18.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:*",
"matchCriteriaId": "C0DA83D6-F16D-47B4-B817-1591FB60E5E6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "6976AFEA-CD46-41A2-B52D-67FA8D4481D5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]