CVE-2025-8099: Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.
Other sources
GitLab has remediated an issue that, under certain conditions, could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-8099?
CVE-2025-8099 is classified as a Denial of Service vulnerability due to its potential to disrupt the operation of GitLab.
How do I fix CVE-2025-8099?
To remediate CVE-2025-8099, upgrade to GitLab version 18.6.6, 18.7.4, or 18.8.4, as these versions contain the necessary patches.
Which versions of GitLab are affected by CVE-2025-8099?
CVE-2025-8099 affects all GitLab versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4.
Is CVE-2025-8099 exploitable by authenticated users?
CVE-2025-8099 can be exploited by unauthenticated users, potentially leading to a Denial of Service.
What kind of impact can CVE-2025-8099 have on GitLab?
CVE-2025-8099 can cause a Denial of Service, rendering the application unresponsive for legitimate users.