CVE-2025-11042Allocation of Resources Without Limits or Throttling in Gitlab

Severity
7.5HIGHNVD
EPSS
0.1%
top 74.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 26

Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while using specific GraphQL queries.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab17.218.2.7+2
NVDgitlab/gitlab17.2.018.2.7+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-v52q-48v6-rmj4: An issue was discovered in GitLab CE/EE affecting all versions starting from 172025-09-26

📋Vendor Advisories

2
GitLab
CVE-2025-11042: An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allo2025-09-26
Debian
CVE-2025-11042: gitlab - An issue was discovered in GitLab CE/EE affecting all versions starting from 17....2025