Database/Control plane, storage & DevOps
GitLab EE: crafted SCIM provisioning input triggers an unbounded loop and takes the instance down
Impact
An authenticated user can send specially crafted input to the SCIM user provisioning feature and drive an unbounded loop, denying service to the GitLab instance. There is no confidentiality or integrity impact in the vendor scoring. Where a self-hosted GitLab is the CI/CD and GitOps source for a GPU fleet, an outage stalls image builds, deployment pipelines and any reconciliation that pulls from it, so the blast radius is larger than the severity number suggests even though nothing is exposed or altered. The advisory says the condition only arises under certain conditions and affects GitLab EE, so instances without SCIM provisioning configured are less exposed.
Who can reach it
Authenticated user with network reach to a GitLab EE instance that has SCIM user provisioning in use. Not exploitable unauthenticated.
What to do
Upgrade to 19.1.7, 19.2.5 or 19.3.1 (or later) - all versions from 11.10 are affected. On a self-managed instance this is a package upgrade and a restart of the GitLab services, with the usual migration window; no node drain or reboot. GitLab.com is already patched.
References
Related entries
- OpenVINO Model Server: An unauthenticated request can drive OpenVINO Model Server into unbounded resource consumptionCVE-2025-22892 · OpenVINO Model ServerMedium
- IBM Storage Scale SMB protocol stack (inherited ACL handling): Files created or modified over SMB inherit permissionsCVE-2025-36104 · IBM Storage Scale SMB protocol stack (inherited ACL handling)Medium
- CephFS (ceph-fuse client): A tenant with an ordinary unprivileged UID on a node that has a CephFS volume mounted viaCVE-2025-52555 · CephFS (ceph-fuse client)Medium
- open-iscsi iscsiuio (DHCPv6 handling): Integer underflow and out-of-bounds read in iscsiuio's DHCPv6 handlingCVE-2026-18727 · open-iscsi iscsiuio (DHCPv6 handling)Medium
- lldpd (802.1Q VLAN tag stripping in lldpd_decode): lldpd strips 802.1Q VLAN tags by memmove-ing the frame payload fourCVE-2026-46433 · lldpd (802.1Q VLAN tag stripping in lldpd_decode)Medium
- Dell OpenManage Server Administrator (relative path traversal): A low-privileged remote attacker reads arbitrary filesCVE-2026-56794 · Dell OpenManage Server Administrator (relative path traversal)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.