CVE-2025-8099 is a denial-of-service vulnerability in GitLab CE/EE, affecting versions before 18.6.6, 18.7.4, and 18.8.4. An unauthenticated attacker can exploit this by sending repeated GraphQL queries, leading to a high-impact denial of service (CVSS 7.5). While the vulnerability has a high FAUCET Risk Score of 91/100, there is currently no evidence of active exploitation, nor are there public exploit modules available in Metasploit or Nuclei. Despite limited community discussion, it has received some media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.8, < 18.6.6CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 18.7, < 18.7.4CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 18.8, < 18.8.4CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 10.8.0, < 18.6.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 10.8.0, < 18.6.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.