CVE-2025-10903

GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have caused denial of service, due to an unbounded loop triggered by specially crafted input in the SCIM user provisioning feature.
References
Link Resource
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/ Release Notes Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/work_items/571842 Issue Tracking Vendor Advisory
https://hackerone.com/reports/3292470 Permissions Required Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:enterprise:*:*:*

History

No history.

Information

Published : 2026-08-26 14:17

Updated : 2026-08-31 15:41


NVD link : CVE-2025-10903

Mitre link : CVE-2025-10903

CVE.ORG link : CVE-2025-10903


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')