CVE-2025-10004

HIGH

GitLab 13.12-18.2.8, 18.3-18.3.4, 18.4-18.4.2 - Denial of Service via Crafted GraphQL Queries

Title source: llm
STIX 2.1

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.

References (3)

Core 3
Core References
Broken Link issue-tracking permissions-required
https://gitlab.com/gitlab-org/gitlab/-/issues/568121
Permissions Required technical-description exploit permissions-required
https://hackerone.com/reports/3026555

Scores

CVSS v3 7.5
EPSS 0.0005
EPSS Percentile 15.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (1)
gitlab/gitlab 13.12.0 - 18.2.8 (2 CPE variants)
Published Oct 09, 2025
Tracked Since Feb 18, 2026