
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-3922 is a Denial of Service vulnerability in the GitLab CE/EE GraphQL API caused by insufficient resource allocation limits. It affects all GitLab CE/EE versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1. The vulnerability was disclosed and patched on April 22, 2026, as part of GitLab's scheduled patch release. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitLab Advisory, GitHub Advisory).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling): the GitLab GraphQL API does not impose adequate restrictions on the size or number of resources that can be allocated per request or session. An authenticated attacker with low privileges can craft GraphQL requests that overwhelm server resources under certain conditions, leading to service exhaustion. No user interaction is required, and the attack is conducted entirely over the network. The vulnerability was reported via HackerOne (report #3098035) by researcher 'pwnie' (GitLab Advisory, GitHub Advisory).
Successful exploitation results in high availability impact — an authenticated attacker can exhaust system resources on the GitLab server, causing denial of service and preventing legitimate users from accessing the platform. There is no confidentiality or integrity impact; the attack is limited to availability disruption. Given the broad version range affected (12.4 through 18.11.0), a large number of self-managed GitLab installations could be impacted (GitLab Advisory, GitHub Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.047% (15th percentile), indicating a low near-term exploitation probability. The vulnerability requires only low-privilege authentication (any registered user), making it accessible to a broad attacker population if credentials are obtained. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, GitLab Advisory).
GitLab has released patched versions addressing this vulnerability: 18.9.6 (for versions 12.4–18.9.x), 18.10.4 (for 18.10.x), and 18.11.1 (for 18.11.x). All self-managed GitLab installations should be upgraded to one of these versions immediately. GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take action. As a temporary workaround if immediate patching is not possible, consider implementing network-level access controls to restrict access to the GraphQL API endpoint to trusted, authenticated users only (GitLab Advisory).
The vulnerability was part of a broader GitLab patch release on April 22, 2026, which addressed 11 vulnerabilities including three high-severity issues. Security media outlets including GBHackers and CyberPress covered the patch release, and the Belgian Centre for Cybersecurity (CCB) issued an advisory urging immediate patching. CISA included the vulnerability in its weekly bulletin (SB26-117) for the week of April 20, 2026 (GitLab Advisory, CCB Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."