CVE-2025-11042: Allocation of Resources Without Limits or Throttling in GitLab
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while using specific GraphQL queries.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to cause uncontrolled CPU consumption, potentially leading to a Denial of Service condition while using specific GraphQL queries.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11042?
CVE-2025-11042 is classified as a high severity vulnerability due to its potential to cause a Denial of Service (DoS) condition.
How do I fix CVE-2025-11042?
To mitigate CVE-2025-11042, users should upgrade their GitLab CE/EE to versions 18.2.7, 18.3.3, or 18.4.1 or later.
What versions are affected by CVE-2025-11042?
CVE-2025-11042 affects GitLab CE/EE versions starting from 17.2 until 18.2.6, 18.3 until 18.3.2, and 18.4 until 18.4.0.
What impact does CVE-2025-11042 have on GitLab?
CVE-2025-11042 can lead to uncontrolled CPU consumption, resulting in a potential Denial of Service (DoS) situation for GitLab instances.
Who can be affected by CVE-2025-11042?
Any user or organization utilizing the affected versions of GitLab CE/EE is at risk of being impacted by CVE-2025-11042.