
CVE-2025-10004 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2025-10004
09 Oct 2025 — GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs. • https://about.gitlab.com/releases/2025/10/08/patch-release-gitlab-18-4-2-released • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2025-2934 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2025-2934
09 Oct 2025 — GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints that send crafted HTTP responses. • https://about.gitlab.com/releases/2025/10/08/patch-release-gitlab-18-4-2-released • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2025-8014 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2025-8014
27 Sep 2025 — Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption. • https://gitlab.com/gitlab-org/gitlab/-/issues/556838 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2025-11042 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2025-11042
26 Sep 2025 — An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while using specific GraphQL queries. • https://gitlab.com/gitlab-org/gitlab/-/issues/550374 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2025-10868 – Business Logic Errors in GitLab
https://notcve.org/view.php?id=CVE-2025-10868
26 Sep 2025 — An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 where certain string conversion methods exhibit performance degradation with large inputs. • https://gitlab.com/gitlab-org/gitlab/-/issues/526482 • CWE-840: Business Logic Errors •

CVE-2025-7691 – Privilege Defined With Unsafe Actions in GitLab
https://notcve.org/view.php?id=CVE-2025-7691
26 Sep 2025 — A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 that could have allowed a developer with specific group management permissions to escalate their privileges and obtain unauthorized access to additional system capabilities. • https://gitlab.com/gitlab-org/gitlab/-/issues/555786 • CWE-267: Privilege Defined With Unsafe Actions •

CVE-2025-9642 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
https://notcve.org/view.php?id=CVE-2025-9642
26 Sep 2025 — An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover. • https://gitlab.com/gitlab-org/gitlab/-/issues/566505 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2025-9958 – Insertion of Sensitive Information Into Sent Data in GitLab
https://notcve.org/view.php?id=CVE-2025-9958
26 Sep 2025 — An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations. • https://gitlab.com/gitlab-org/gitlab/-/issues/567777 • CWE-201: Insertion of Sensitive Information Into Sent Data •

CVE-2025-10858 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2025-10858
26 Sep 2025 — An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that allows unauthenticated users to cause a Denial of Service (DoS) condition while uploading specifically crafted large JSON files. • https://gitlab.com/gitlab-org/gitlab/-/issues/570034 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2025-10871 – Missing Authorization in GitLab
https://notcve.org/view.php?id=CVE-2025-10871
26 Sep 2025 — An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintainers can exploit a vulnerability where they can assign custom roles to users with permissions exceeding their own, effectively granting themselves elevated privileges. • https://gitlab.com/gitlab-org/gitlab/-/issues/569482 • CWE-862: Missing Authorization •