CVE-2025-10868: Business Logic Errors in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 where certain string conversion methods exhibit performance degradation with large inputs.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to cause performance degradation, potentially leading to a Denial of Service condition with certain string conversion methods.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10868?
CVE-2025-10868 has been classified as a medium-severity vulnerability due to performance degradation issues.
What versions of GitLab are affected by CVE-2025-10868?
CVE-2025-10868 affects GitLab CE/EE versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1.
How do I fix CVE-2025-10868?
To resolve CVE-2025-10868, upgrade GitLab CE/EE to version 18.2.7, 18.3.3, or 18.4.1 or later.
What is the impact of CVE-2025-10868?
The impact of CVE-2025-10868 is mainly performance degradation when processing large inputs in certain string conversion methods.
Is there a workaround for CVE-2025-10868?
There is no documented workaround for CVE-2025-10868; updating to a patched version is recommended.