Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to cause a denial of service by making the GitLab instance unresponsive due to improper input validation in GraphQL request processing.
Problem types
CWE-407: Inefficient Algorithmic Complexity
Product status
18.5 (semver) before 18.8.7
18.9 (semver) before 18.9.3
18.10 (semver) before 18.10.1
Credits
Thanks [svalkanov](https://hackerone.com/svalkanov) for reporting this vulnerability through our HackerOne bug bounty program
References
gitlab.com/gitlab-org/gitlab/-/work_items/593140
hackerone.com/reports/3597342 (HackerOne Bug Bounty Report #3597342)
about.gitlab.com/...5/patch-release-gitlab-18-10-1-released/