SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2025-10903

MEDIUM · CVSS 6.5 EPSS 0.41%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

GitLab's SCIM user provisioning feature is vulnerable to a denial of service attack, which can be triggered by an authenticated user sending specially crafted input, leading to an unbounded loop. This affects all versions from 11.10 up to 19.1.7, 19.2 up to 19.2.5, and 19.3 up to 19.3.1. Organizations using these versions should prioritize remediation to prevent potential service disruptions.

CVE
CVE-2025-10903
Severity
MEDIUM
CVSS
6.5
EPSS
0.41%
GitLab

Original NVD Description

GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have caused denial of service, due to an unbounded loop triggered by specially crafted input in the SCIM user provisioning feature.

Related CVEs

Other vulnerabilities affecting the same vendor(s)