CVE-2025-2256
HIGHGitLab CE/EE <18.1.6-18.3.2 - DoS
Title source: llmDescription
An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.
Scores
CVSS v3
7.5
EPSS
0.0004
EPSS Percentile
11.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-1284
Status
published
Affected Products (2)
gitlab/gitlab
< 18.1.6
gitlab/gitlab
< 18.1.6
Timeline
Published
Sep 12, 2025
Tracked Since
Feb 18, 2026