HIGH

CVE-2025-2256

Gitlab GitLab 2025-09-12 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.

Summary dbcve.org

A denial of service vulnerability in GitLab CE/EE allows unauthenticated attackers to send multiple concurrent large SAML authentication responses that consume excessive server resources, rendering the instance unresponsive to legitimate users.

Mitigation

Upgrade GitLab to version 18.1.6, 18.2.6, or 18.3.2 or later. Consider implementing rate limiting on SAML endpoints as a temporary mitigation while planning the upgrade.

Weakness (CWE)

CWE-1284

EPSS Score

0.5%
Probability of exploitation in next 30 days
42th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE