GitLab has disclosed multiple serious Denial-of-Service (DoS) that could allow unauthenticated attackers to take down self-managed installations.
See also: GitLab security update fixes multiple vulnerabilities

These vulnerabilities affect Community Edition (CE) and Enterprise Edition (EE) prior to 18.4.1, 18.3.3 , and 18.2.7, and exploit both HTTP endpoints and GraphQL APIs. Administrators should upgrade immediately to prevent service outages and potential data loss.
Two of the most serious issues, CVE-2025-10858 and CVE-2025-8014, have a CVSS score of 7.5 and allow unauthenticated Denial-of-Service via malformed JSON payloads and bypassing GraphQL query complexity limits.
In CVE-2025-10858, attackers can send a specially crafted JSON file to endpoints such as /api/v4/projects/:id/uploads to exhaust CPU and memory, rendering the Rails web server unresponsive. The vulnerability could cause unintentional damage to co-hosted services on multi-tenant systems and does not require authentication.
See also: DevSecOps: GitLab fixes multiple vulnerabilities

Similarly, CVE-2025-8014 exploits unconstrained GraphQL queries. By constructing deeply nested or overly complex queries against /api/graphql, an attacker can exceed internal query cost limits, causing a crash loop in the unicorn worker pool. The vulnerability also affects self-managed GitLab installations and internal graphs, potentially disrupting CI/CD pipelines.
Additional medium severity issues, including CVE-2025-9958 (CVSS 6.8) and CVE-2025-7691 (CVSS 6.5), allow information disclosure and privilege escalation. CVE-2025-9958 exposes virtual registry configurations to low-privileged users via the /api/v4/registry/repositories/:id, potentially leaking registry tokens. CVE-2025-7691 allows developers with group management privileges to escalate privileges via crafted API calls to /api/v4/groups/:group_id/members, bypassing role checks in the EE backend.
Several additional DoS factors in unconstrained GraphQL array parameters, blobSearch, and string conversion methods carry lower CVSS scores but still risk performance degradation. The GraphQL resolver for blobSearch can enter an infinite loop on specially crafted queries, while recursive string conversion in GitLab's Ruby middleware can exhaust Ruby VM resources .
See also: GitLab Duo vulnerability allows manipulation of AI responses

Today's patch release updates GitLab CE and EE to versions 18.4.1, 18.3.3 , and 18.2.7, incorporating critical bug and security fixes. GitLab Dedicated customers are already on the updated versions. Self-managed installations should be upgraded without delay. Maintainers should ensure timely application of these patches to maintain the integrity and availability of your GitLab installation.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
