GitLab EE Denial-of-Service Vulnerability in GraphQL API

Vulnerability

A denial-of-service vulnerability has been identified in GitLab Enterprise Edition (EE) versions 18.2 prior to 18.8.9, 18.9 prior to 18.9.5, and 18.10 prior to 18.10.3. This vulnerability allowed an authenticated user to disrupt the GitLab instance by sending improperly validated GraphQL queries, which could have led to increased resource consumption and potential service degradation.

Impact

Exploitation of this vulnerability could have caused a denial-of-service condition, disrupting normal operations of the GitLab instance and potentially leading to increased resource usage.

Remediation

Users are advised to upgrade to GitLab EE versions 18.10.3, 18.9.5, or 18.8.9. Instructions for updating GitLab can be found on the GitLab Update page. Note that these patch releases do not require any downtime for multi-node deployments.

Added: Apr 9, 2026, 12:27 AM
Updated: Apr 9, 2026, 12:27 AM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
5.2
remediation
7.7
relevance
5.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.