CVE-2025-3922: Denial of Service issue in GraphQL API impacts GitLab CE/EE
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service by overwhelming system resources under certain conditions due to insufficient resource allocation limits in the GraphQL API.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to cause denial of service by overwhelming system resources under certain conditions due to insufficient resource allocation limits in the GraphQL API.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-3922?
CVE-2025-3922 is classified as a Denial of Service (DoS) vulnerability affecting multiple versions of GitLab CE and EE.
How do I fix CVE-2025-3922?
To remediate CVE-2025-3922, upgrade to GitLab CE/EE version 18.9.6, 18.10.4, or 18.11.1.
What versions are affected by CVE-2025-3922?
CVE-2025-3922 affects GitLab CE/EE versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1.
Can an unauthenticated user exploit CVE-2025-3922?
No, CVE-2025-3922 requires an authenticated user to exploit the vulnerability.
What is a Denial of Service vulnerability in the context of CVE-2025-3922?
In the context of CVE-2025-3922, a Denial of Service vulnerability allows an authenticated user to overwhelm the GitLab system and disrupt its normal operations.