Junglewise Threat Intelligence

CVE-2025-12664: GitLab CE/EE denial of service in GraphQL API

CVE-2025-12664 · Severity: high · CVSS 7.5 · Published 2026-04-08

Technologies: GitLab CE, GitLab EE. Vendors: GitLab.

Executive brief

GitLab has fixed a security vulnerability in its Community and Enterprise editions that could allow an attacker to crash or slow down the service. By sending a high volume of specific database queries, an unauthenticated user could overwhelm the system, making the platform unavailable to legitimate users. This impacts organizations relying on GitLab for software development and collaboration by potentially disrupting operations.

Technical details

A denial of service (DoS) vulnerability exists in GitLab CE/EE due to improper validation of specified quantities in GraphQL API inputs (CWE-1284). An unauthenticated remote attacker can exploit this by sending repeated, resource-intensive GraphQL queries to the server. This can lead to resource exhaustion, effectively making the GitLab instance unresponsive to legitimate traffic. The issue affects versions starting from 13.0 and has been patched in versions 18.8.9, 18.9.5, and 18.10.3. No user interaction or special privileges are required for exploitation.

Affected products

  • GitLab GitLab CE/EE 13.0 to 18.8.8, 18.9 to 18.9.4, 18.10 to 18.10.2

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: patched
  • 2026-04-08: advisory

References

Related threats