MEDIUM
CVE-2020-26409
CVSS
6.5
Description
A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.
Summary dbcve.org
A denial of service vulnerability exists in GitLab CE/EE's markdown processing where input validation can be bypassed, allowing attackers to submit specially crafted markdown content that triggers uncontrolled resource consumption.
Mitigation
Upgrade GitLab to version 13.4.7, 13.5.5, or 13.6.2 (or later) to patch the vulnerability in the markdown field validation.
Weakness (CWE)
CWE-20
Improper Input Validation
CWE-400
Uncontrolled Resource Consumption
EPSS Score
1.26%
Probability of exploitation in next 30 days
68.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.