Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.
Conclusion & alert: CVE-2025-8014 is rated Moderate Risk (45.1/100): CVSS High severity, with low exploitation likelihood (EPSS 0.56%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.16% | 0.56% | +0.40% |
| 2 | 2026-06-02 | 0.15% | 0.16% | +0.01% |
| 3 | 2026-05-03 | — | 0.15% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2025-8014 not yet assigned priority: Debian including 1 source packages (gitlab), 1 status rows across 1 suites (sid): open 1. | https://security-tracker.debian.org/tracker/CVE-2025-8014 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| gitlab | gitlab | >= 11.10.0, < 18.2.7 | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
| gitlab | gitlab | >= 11.10.0, < 18.2.7 | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
| gitlab | gitlab | >= 18.3.0, < 18.3.3 | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
| gitlab | gitlab | >= 18.3.0, < 18.3.3 | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
| gitlab | gitlab | 18.4.0 | cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:community:*:*:* |
| gitlab | gitlab | 18.4.0 | cpe:2.3:a:gitlab:gitlab:18.4.0:*:*:*:enterprise:*:*:* |
| URL | Tags |
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/556838 | Broken Link |
| https://hackerone.com/reports/3228134 | Permissions Required |