CVE-2025-10903: Loop with Unreachable Exit Condition ('Infinite Loop') in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have caused denial of service, due to an unbounded loop triggered by specially crafted input in the SCIM user provisioning feature.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.2.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.3.1
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
GitLab EE deployments running versions from 11.10 up to, but excluding, 19.1.7, 19.2.5, or 19.3.1 are affected. The issue is associated with the SCIM user provisioning feature.
What does an attacker need to exploit it?
An attacker needs to be authenticated and able to submit specially crafted input that triggers the unbounded loop in SCIM user provisioning. No user interaction is required.
What is the operational impact of successful exploitation?
Successful exploitation can cause denial of service through an infinite or unbounded loop. The provided severity vector indicates availability impact only, with no stated confidentiality or integrity impact.
What versions remediate the issue?
Upgrade to GitLab EE 19.1.7, 19.2.5, 19.3.1, or a later version in the applicable release line.