An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while using specific GraphQL queries.
2025-09-26T10:15:47.003
2025-09-29T13:11:50.067
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | gitlab | gitlab | < 18.2.7 | Yes |
| Application | gitlab | gitlab | < 18.2.7 | Yes |
| Application | gitlab | gitlab | < 18.3.3 | Yes |
| Application | gitlab | gitlab | < 18.3.3 | Yes |
| Application | gitlab | gitlab | 18.4.0 | Yes |
| Application | gitlab | gitlab | 18.4.0 | Yes |