CVE-2025-2256
An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.50% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1284
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://about.gitlab.com/releases/2025/09/10/patch-release-gitlab-18-3-2-released/Release Notes, Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/524633Broken Link
- https://hackerone.com/reports/3019485Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.