Back

HIGH

Inefficient Regular Expression Complexity in GitLab

Published Apr 25, 2024

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.5 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. A crafted wildcard filter in FileFinder may lead to a denial of service.

Affected products

Remediation

Vendor solution

Upgrade to versions 16.9.6, 16.10.4, 16.11.1 or above.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Apr 25, 2024
Updated Nov 20, 2025
Reserved Mar 22, 2024
CISA Vulnrichment
Updated Apr 30, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 25, 2024