CVE-2025-8014

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:*

History

03 Oct 2025, 18:23

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/gitlab/-/issues/556838 - () https://gitlab.com/gitlab-org/gitlab/-/issues/556838 - Broken Link
References () https://hackerone.com/reports/3228134 - () https://hackerone.com/reports/3228134 - Permissions Required
First Time Gitlab gitlab
Gitlab
CPE cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*

27 Sep 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-27 17:15

Updated : 2025-10-03 18:23


NVD link : CVE-2025-8014

Mitre link : CVE-2025-8014

CVE.ORG link : CVE-2025-8014


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-770

Allocation of Resources Without Limits or Throttling