References https://avd.aliyun.com/detail?id=AVD-2025-9484 https://cve.imfht.com/detail/CVE-2025-5846 https://cve.imfht.com/detail/CVE-2025-2246 https://zeropath.com/blog/cve-2025-11340-gitlab-graphql-authorization-brief https://www.sentinelone.com/vulnerability-database/cve-2025-9484/ https://docs.gitlab.com/releases/18_10_1/ https://www.sentinelone.com/vulnerability-database/cve-2025-10004/ https://mojoauth.com/news/gitlab-security-update-critical-patches-for-dos-and-auth-bypass https://advisory.eventussecurity.com/advisory/gitlab-graphql-api-vulnerabilities-allow-unauthorized-actions-and-denial-of-service/ https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/GitLab-Graphql%E9%82%AE%E7%AE%B1%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E-CVE-2020-26413.md
Related VulnerabilitiesPoCCVE-2026-85706: GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File ReadGitLab CE/EE /api/graphql 未授权访问漏洞(CVE-2026-19478)PoCCVE-2026-19478: GitLab CE/EE - GraphQL @gl_introduced Arbitrary Method InvocationPoCCVE-2021-22175: GitLab CI Lint API - Server-Side Request ForgeryTraggoServer /graphql 默认口令漏洞GitLab GitLab CE/EE 权限管理不当漏洞GitLab CE/EE 资源分配控制不当漏洞 可导致拒绝服务gitlab-api-user-enum: GitLab - User Information Disclosure Via Open APIPoCCVE-2024-45409: GitLab - SAML Authentication BypassPoCCVE-2025-25291: GitLab - SAML Authentication BypassPoCCVE-2019-6793: GitLab Enterprise Edition - Server-Side Request ForgeryPoCCVE-2019-9879: WPGraphQL 0.2.3 - User Creation