Junglewise Threat Intelligence

CVE-2025-10903: GitLab Enterprise Edition denial of service in SCIM API

CVE-2025-10903 · Severity: medium · CVSS 6.5 · Published 2026-08-26

Technologies: GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab Enterprise Edition's SCIM user provisioning feature contains a denial of service vulnerability that allows an authenticated user to trigger an unbounded loop with maliciously crafted input. An attacker could exploit this to make the SCIM provisioning service unavailable, disrupting user management and identity synchronization for organizations relying on this feature.

Technical details

The vulnerability is a denial of service issue in the SCIM (System for Cross-domain Identity Management) API user provisioning feature caused by an unbounded loop triggered by specially crafted input. It requires authentication to exploit and impacts GitLab EE versions 11.10 through 19.1.7, 19.2.0 through 19.2.5, and 19.3.0 through 19.3.1. An authenticated user without additional privileges can send malicious input to the SCIM API endpoint, causing the service to enter an infinite or excessively long loop that consumes resources and renders the provisioning feature unavailable. The issue has been patched in versions 19.1.7, 19.2.5, and 19.3.1.

Affected products

  • GitLab GitLab Enterprise Edition 11.10 before 19.1.7, 19.2 before 19.2.5, 19.3 before 19.3.1

Timeline

  • 2026-08-26: disclosed
  • 2026-08-26: patched: Patches released for versions 19.1.7, 19.2.5, and 19.3.1

References

Related threats