CVE-2025-10867: Allocation of Resources Without Limits or Throttling in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to create a denial-of-service condition by exploiting an unprotected GraphQL API through repeated requests.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to create a Denial of Service condition by exploiting an unprotected GraphQL API through repeated requests.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10867?
CVE-2025-10867 is considered a high-severity vulnerability due to its potential to cause denial-of-service conditions.
How do I fix CVE-2025-10867?
To fix CVE-2025-10867, upgrade GitLab CE/EE to versions 18.2.7, 18.3.3, or 18.4.1 or later.
Which versions are affected by CVE-2025-10867?
CVE-2025-10867 affects GitLab CE versions prior to 18.2.7, and GitLab EE versions prior to 18.3.3 and 18.4.1.
Who is impacted by CVE-2025-10867?
Authenticated users of GitLab CE/EE versions from 18.1 through 18.4.1 are impacted by CVE-2025-10867.
What type of vulnerability is CVE-2025-10867?
CVE-2025-10867 is a denial-of-service (DoS) vulnerability targeting an unprotected GraphQL API in GitLab.