CVE-2025-8014

HIGH

GitLab 11.10-18.2.6, 18.3-18.3.2, 18.4-18.4.0 - Unauthenticated Denial of Service via GraphQL Query Complexity Bypass

Title source: llm
STIX 2.1

Description

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.

References (2)

Core 2
Core References
Broken Link issue-tracking permissions-required
https://gitlab.com/gitlab-org/gitlab/-/issues/556838
Permissions Required technical-description exploit permissions-required
https://hackerone.com/reports/3228134

Scores

CVSS v3 7.5
EPSS 0.0015
EPSS Percentile 34.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (2)
gitlab/gitlab 18.4.0 (2 CPE variants)
gitlab/gitlab 11.10.0 - 18.2.7 (2 CPE variants)
Published Sep 27, 2025
Tracked Since Feb 18, 2026