Denial-of-Service Vulnerability in GitLab CE/EE by GitLab
CVE-2025-10867

3.5LOW

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
26 September 2025

What is CVE-2025-10867?

In GitLab CE/EE versions prior to 18.2.7, 18.3.3, and 18.4.1, an authenticated user could exploit an unprotected GraphQL API endpoint to launch repeated requests, potentially leading to a denial-of-service condition. This issue raises serious concerns regarding the security and resilience of applications relying on GitLab's platform.

Affected Version(s)

GitLab 18.1 < 18.2.7

GitLab 18.3 < 18.3.3

GitLab 18.4 < 18.4.1

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability has been discovered internally by GitLab team member Terri Chu
.
CVE-2025-10867 : Denial-of-Service Vulnerability in GitLab CE/EE by GitLab