CVE-2025-2256: Improper Validation of Specified Quantity in Input in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.
Other sources
GitLab has remediated an issue that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-2256?
CVE-2025-2256 has a medium severity rating due to its potential to make the GitLab instance unresponsive.
How do I fix CVE-2025-2256?
To fix CVE-2025-2256, upgrade GitLab CE/EE to version 18.1.6, 18.2.6, or 18.3.2 or later.
Which versions of GitLab are affected by CVE-2025-2256?
CVE-2025-2256 affects GitLab CE/EE versions from 7.12 to before 18.1.6, 18.2 to before 18.2.6, and 18.3 to before 18.3.2.
What kind of attack does CVE-2025-2256 describe?
CVE-2025-2256 describes an issue that allows unauthorized users to overload the GitLab instance by sending multiple concurrent large SAML requests.
Is CVE-2025-2256 exploitable remotely?
Yes, CVE-2025-2256 can be exploited remotely by sending malicious requests to the affected GitLab instance.