Security Advisory

CVE-2025-10867

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-09-26 09:04:26
Last updated 2025-09-26 15:33:34
Assigner GitLab
CVSS score 3.5
State PUBLISHED

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to create a denial-of-service condition by exploiting an unprotected GraphQL API through repeated requests.