Back

MEDIUM

Inefficient Regular Expression Complexity in GitLab

Published Apr 12, 2024

Description

A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature.

Affected products

Remediation

Vendor solution

Upgrade to versions 16.8.6, 16.9.4, 16.10.2 or above.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Apr 12, 2024
Updated Aug 14, 2026
Reserved Dec 4, 2023
CISA Vulnrichment
Updated Jul 8, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a