CVE-2025-8014: Allocation of Resources Without Limits or Throttling in GitLab
Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to bypass query complexity limits leading to a Denial of Service condition.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-8014?
CVE-2025-8014 is classified as a Denial of Service vulnerability affecting GitLab EE/CE.
How can I mitigate CVE-2025-8014?
To mitigate CVE-2025-8014, upgrade to GitLab version 18.2.7, 18.3.3, or 18.4.1 or later.
Which versions are affected by CVE-2025-8014?
CVE-2025-8014 affects GitLab EE/CE versions from 11.10 to prior to 18.2.7, 18.3 to prior to 18.3.3, and 18.4 to prior to 18.4.1.
What types of users are impacted by CVE-2025-8014?
CVE-2025-8014 allows unauthenticated users to cause potential resource exhaustion and service disruption.
What is the nature of the attack in CVE-2025-8014?
CVE-2025-8014 involves bypassing query complexity limits in GraphQL endpoints, leading to Denial of Service.