High severity7.5NVD Advisory· Published Sep 27, 2025· Updated Jun 17, 2026
CVE-2025-8014
CVE-2025-8014
Description
Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 11.10
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=11.10.0,<18.2.7
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=11.10.0,<18.2.7
- cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:*
- (no CPE)range: from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1
- Range: from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1
- osv-coords9 versionspkg:apk/chainguard/gitlab-rails-ce-18.1pkg:apk/chainguard/gitlab-rails-ce-assets-18.1pkg:apk/chainguard/gitlab-rails-ce-assets-fips-18.1pkg:apk/chainguard/gitlab-rails-ce-doc-18.1pkg:apk/chainguard/gitlab-rails-ce-doc-fips-18.1pkg:apk/chainguard/gitlab-rails-ce-fips-18.1pkg:apk/chainguard/gitlab-workhorse-ce-18.1pkg:apk/chainguard/gitlab-workhorse-ce-fips-18.1pkg:bitnami/gitlab
< 18.1.6-r3+ 8 more
- (no CPE)range: < 18.1.6-r3
- (no CPE)range: < 18.1.6-r3
- (no CPE)range: < 18.1.6-r4
- (no CPE)range: < 18.1.6-r3
- (no CPE)range: < 18.1.6-r4
- (no CPE)range: < 18.1.6-r4
- (no CPE)range: < 18.1.6-r3
- (no CPE)range: < 18.1.6-r4
- (no CPE)range: >= 11.10.0, < 18.2.7
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/556838nvdBroken Link
- hackerone.com/reports/3228134nvdPermissions Required
News mentions
1- GitLab Patch Release: 18.4.1, 18.3.3, 18.2.7GitLab Security Releases · Sep 25, 2025