Intel

AIKIDO-2026-535051

gitlab-ce is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2025-14871 Published 3 days ago

75

High Risk

This Affects:

OSgitlab-ce
18.4.6 - 19.1.7
Fixed in 19.1.8
19.2.0 - 19.2.5
Fixed in 19.2.6
19.3.0 - 19.3.1
Fixed in 19.3.2
Are you affected? Scan for Free

TL;DR

GraphQL complexity calculation does not enforce adequate resource allocation limits. An unauthenticated user can submit queries that exhaust resources and cause denial of service. The fix tightens GraphQL complexity limiting so oversized queries are rejected before they can overwhelm the instance.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

gitlab-ce is vulnerable to Denial of Service (DoS) in versions 18.4.6 - 19.1.7, 19.2.0 - 19.2.5 and 19.3.0 - 19.3.1.

How to fix this

Upgrade the gitlab-ce library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform