CVE-2025-10004: Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.
Other sources
GitLab has remediated an issue that could make the GitLab instance unresponsive or degraded by sending crafted GraphQL queries requesting large repository blobs.Impacted Versions: GitLab CE/EE: all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2CVSS: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10004?
CVE-2025-10004 is classified as a critical vulnerability due to its potential to cause the GitLab instance to become unresponsive or severely degraded.
How do I fix CVE-2025-10004?
To remediate CVE-2025-10004, upgrade to GitLab versions 18.2.9, 18.3.5, or 18.4.3 and later.
What versions of GitLab are affected by CVE-2025-10004?
CVE-2025-10004 affects GitLab CE/EE versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2.
What kind of attacks are possible with CVE-2025-10004?
CVE-2025-10004 can allow attackers to send crafted GraphQL queries that request large repository blobs, leading to service degradation.
Is CVE-2025-10004 a known issue in previous GitLab versions?
Yes, CVE-2025-10004 has been acknowledged and remediated by GitLab in the affected versions mentioned.