GPU VulnDB

Database/Control plane, storage & DevOps

GitLab EE: crafted SCIM provisioning input triggers an unbounded loop and takes the instance down

CVE-2025-10903Control plane, storage & DevOpscurated

Impact

An authenticated user can send specially crafted input to the SCIM user provisioning feature and drive an unbounded loop, denying service to the GitLab instance. There is no confidentiality or integrity impact in the vendor scoring. Where a self-hosted GitLab is the CI/CD and GitOps source for a GPU fleet, an outage stalls image builds, deployment pipelines and any reconciliation that pulls from it, so the blast radius is larger than the severity number suggests even though nothing is exposed or altered. The advisory says the condition only arises under certain conditions and affects GitLab EE, so instances without SCIM provisioning configured are less exposed.

Who can reach it

Authenticated user with network reach to a GitLab EE instance that has SCIM user provisioning in use. Not exploitable unauthenticated.

What to do

Upgrade to 19.1.7, 19.2.5 or 19.3.1 (or later) - all versions from 11.10 are affected. On a self-managed instance this is a package upgrade and a restart of the GitLab services, with the usual migration window; no node drain or reboot. GitLab.com is already patched.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.