CVE-2025-8014

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-8014
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8014.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-8014
Aliases
Published
2025-09-27T16:33:32.601Z
Modified
2025-12-05T10:59:00.391502Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Allocation of Resources Without Limits or Throttling in GitLab
Details

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.

Database specific
{
    "cwe_ids": [
        "CWE-770"
    ],
    "cna_assigner": "GitLab",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8014.json"
}
References

Affected packages

Git / gitlab.com/gitlab-org/gitlab

Affected ranges

Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
{
    "versions": [
        {
            "introduced": "11.10"
        },
        {
            "fixed": "18.2.7"
        }
    ]
}
Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
{
    "versions": [
        {
            "introduced": "18.3"
        },
        {
            "fixed": "18.3.3"
        }
    ]
}
Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
{
    "versions": [
        {
            "introduced": "18.4"
        },
        {
            "fixed": "18.4.1"
        }
    ]
}

Affected versions

v18.*

v18.3.0-ee
v18.3.1-ee
v18.3.2-ee
v18.4.0-ee