PoC Index

CVE-2025-8014

HIGH 7.5EPSS 0.6%

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
0.59% chance of exploitation in the next 30 days, 46th percentile
Published
2025-09-27
Updated
2025-09-30

Proof-of-concept exploits (1)

References

Related