Back

MEDIUM

Inefficient Regular Expression Complexity in GitLab

Published May 23, 2024

Description

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. It is possible for an attacker to cause a denial of service using a crafted wiki page.

Affected products

Remediation

Vendor solution

Upgrade to versions 16.10.6, 16.11.3, 17.0.1 or above.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published May 23, 2024
Updated Oct 3, 2024
Reserved Dec 4, 2023
CISA Vulnrichment
Updated May 23, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a