Database/Control plane, storage & DevOps
GitLab: unauthenticated GraphQL requests exhaust resources through faulty complexity limits
Impact
Improper resource allocation limits in GitLab's GraphQL complexity calculation let an unauthenticated caller drive the instance into denial of service. GitLab assigned two ids for this in the same patch release with identical descriptions and version ranges (CVE-2026-1168 is the other, from a separate HackerOne report); an operator takes one action for both, so they are recorded together here. For a GPU fleet the cost is not the web UI but the CI/CD and GitOps path that hangs off it - image builds, model pipeline triggers and deploys stall while the instance is unavailable. Affects 18.4.6 up to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.
Who can reach it
Anyone who can reach the GitLab GraphQL endpoint over the network, unauthenticated. Instances published to the internet are exposed directly; an instance restricted to an internal VLAN or behind SSO narrows this to that network.
What to do
Upgrade to GitLab 19.1.8, 19.2.6 or 19.3.2 and restart the application - a standard GitLab patch release with no node-level work. If the upgrade cannot land now, put rate limiting in front of the GraphQL endpoint and restrict unauthenticated access to it.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- OpenVPN: Corrupting and replaying early-handshake packets against a tls-crypt-v2 serverCVE-2025-2704 · OpenVPNHigh
- Apache Kafka (client): SASL/OAUTHBEARER endpoint URLs accept file://CVE-2025-27817 · Apache Kafka (client)High
- HPE Insight Remote Support (unauthenticated denial of service): An unauthenticated attacker takes Insight RS downCVE-2025-37097 · HPE Insight Remote Support (unauthenticated denial of service)High
- HPE Insight Remote Support (path traversal): Unauthenticated path traversal disclosing files from the IRS serverCVE-2025-37098 · HPE Insight Remote Support (path traversal)High
- Citrix NetScaler ADC/Gateway: "CitrixBleed 2" - insufficient input validationCVE-2025-5777 · Citrix NetScaler ADC/GatewayHigh
- Go crypto/x509 (Tailscale, Go infra): Name-constraint checking scales non-linearly with certificate sizeCVE-2025-58187 · Go crypto/x509 (Tailscale, Go infra)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.