Denial of Service Vulnerability in GitLab Community and Enterprise Editions
CVE-2025-11042
4.3MEDIUM
What is CVE-2025-11042?
A vulnerability exists in GitLab Community and Enterprise Editions which can be exploited by an attacker to induce excessive CPU consumption through specific GraphQL queries. This could ultimately lead to a Denial of Service (DoS) condition, impacting the availability of the affected services. It is critical for users and administrators to update to the latest versions where this issue has been addressed to mitigate potential risks.
Affected Version(s)
GitLab 17.2 < 18.2.7
GitLab 18.3 < 18.3.3
GitLab 18.4 < 18.4.1
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability has been discovered internally by GitLab team member [Alisa Frunza](https://gitlab.com/afrnz).