6.5

CVE-2025-10903

Exploit

Loop with Unreachable Exit Condition ('Infinite Loop') in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have caused denial of service, due to an unbounded loop triggered by specially crafted input in the SCIM user provisioning feature.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition enterprise Version >= 11.1.0 < 19.1.7
Gitlab ≫ GitLab SwEdition enterprise Version >= 19.2.0 < 19.2.5
Gitlab ≫ GitLab Version 19.3.0 SwEdition enterprise
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.351
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cve@gitlab.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

https://hackerone.com/reports/3292470
Third Party Advisory
Permissions Required
https://gitlab.com/gitlab-org/gitlab/-/work_items/571842
Vendor Advisory
Issue Tracking
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/
Vendor Advisory
Release Notes