{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-10004","assignerOrgId":"ceab7361-8a18-47b1-92ba-4d7d25f6715a","state":"PUBLISHED","assignerShortName":"GitLab","dateReserved":"2025-09-04T18:33:25.673Z","datePublished":"2025-10-09T12:04:30.109Z","dateUpdated":"2025-10-09T13:16:38.980Z"},"containers":{"cna":{"title":"Allocation of Resources Without Limits or Throttling in GitLab","descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs."}],"affected":[{"vendor":"GitLab","product":"GitLab","repo":"git://git@gitlab.com:gitlab-org/gitlab.git","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"versions":[{"version":"13.12","status":"affected","lessThan":"18.2.8","versionType":"semver"},{"version":"18.3","status":"affected","lessThan":"18.3.4","versionType":"semver"},{"version":"18.4","status":"affected","lessThan":"18.4.2","versionType":"semver"}],"defaultStatus":"unaffected"}],"problemTypes":[{"descriptions":[{"lang":"en","description":"CWE-770: Allocation of Resources Without Limits or Throttling","cweId":"CWE-770","type":"CWE"}]}],"references":[{"url":"https://about.gitlab.com/releases/2025/10/08/patch-release-gitlab-18-4-2-released/"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/568121","name":"GitLab Issue #568121","tags":["issue-tracking","permissions-required"]},{"url":"https://hackerone.com/reports/3026555","name":"HackerOne Bug Bounty Report #3026555","tags":["technical-description","exploit","permissions-required"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}],"solutions":[{"lang":"en","value":"Upgrade to version 18.2.8, 18.3.4 or 18.4.2"}],"credits":[{"lang":"en","value":"Thanks [pwnie](https://hackerone.com/pwnie) for reporting this vulnerability through our HackerOne bug bounty program","type":"finder"}],"providerMetadata":{"orgId":"ceab7361-8a18-47b1-92ba-4d7d25f6715a","shortName":"GitLab","dateUpdated":"2025-10-09T12:04:30.109Z"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-10-09T13:15:06.752510Z","id":"CVE-2025-10004","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-09T13:16:38.980Z"}}]}}