Medium severity6.5NVD Advisory· Published Aug 26, 2026· Updated Aug 31, 2026
CVE-2025-10903
CVE-2025-10903
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have caused denial of service, due to an unbounded loop triggered by specially crafted input in the SCIM user provisioning feature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4(expand)+ 1 more
- (no CPE)
- (no CPE)range: from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1
- Range: from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1
Patches
Vulnerability mechanics
References
2- docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/nvdRelease NotesVendor Advisory
- hackerone.com/reports/3292470nvdPermissions RequiredThird Party Advisory
News mentions
3- GitLab EE: Five Vulnerabilities Including High-Severity Command Execution Patched TogetherVypr Intelligence · Aug 26, 2026
- GitLab EE: Three Vulnerabilities Including Auth Bypass and DoS Patched TogetherVypr Intelligence · Aug 26, 2026
- GitLab Patch Release: 19.3.1, 19.2.5, 19.1.7GitLab Security Releases · Aug 26, 2026