CVE-2025-10094: Improper Validation of Specified Quantity in Input in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrative operations by creating tokens with excessively large names.
Other sources
GitLab has remediated an issue that could have allowed authenticated users to disrupt access to token listings and related administrative operations by creating tokens with excessively large names.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10094?
CVE-2025-10094 is categorized with a high severity due to the potential for authenticated users to disrupt access to token listings.
How do I fix CVE-2025-10094?
To fix CVE-2025-10094, upgrade to GitLab versions 18.1.6, 18.2.6, or 18.3.2 or later.
Who is affected by CVE-2025-10094?
CVE-2025-10094 affects all versions of GitLab CE/EE from 10.7 up to but not including 18.1.6, 18.2 up to but not including 18.2.6, and 18.3 up to but not including 18.3.2.
What type of vulnerability is CVE-2025-10094?
CVE-2025-10094 is an authentication vulnerability that allows disruption of administrative operations.
What are the implications of CVE-2025-10094?
The implications of CVE-2025-10094 include unauthorized disruption of token management processes for authenticated users.