CVE-2025-8014
Last modified
CVE-2025-8014 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 11.10.0, < 18.2.7 |
| Gitlab | Gitlab | >= 18.3.0, < 18.3.3 |
| Gitlab | Gitlab | 18.4.0 |
References
- https://hackerone.com/reports/3228134Permissions Required
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-8014?
How severe is CVE-2025-8014?
How do I fix CVE-2025-8014?
Are you affected by CVE-2025-8014?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
