CVE-2025-3279: Allocation of Resources Without Limits or Throttling in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests.
Other sources
GitLab has remediated an issue that, under certain conditions, could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-3279?
CVE-2025-3279 is classified as a moderate severity vulnerability allowing potential denial of service conditions.
How do I fix CVE-2025-3279?
To mitigate CVE-2025-3279, you should upgrade your GitLab CE/EE to versions 17.11.5, 18.0.3, or 18.1.1 or later.
Who is affected by CVE-2025-3279?
CVE-2025-3279 affects all GitLab CE/EE versions from 10.7 up to 17.11.5, 18.0 up to 18.0.3, and 18.1 up to 18.1.1.
What types of attacks can CVE-2025-3279 enable?
CVE-2025-3279 can allow authenticated attackers to create a denial of service (DoS) condition through crafted GraphQL requests.
Is CVE-2025-3279 related to GraphQL?
Yes, CVE-2025-3279 specifically involves a vulnerability that could be exploited through crafted GraphQL requests.