HIGH
CVE-2021-22166
CVSS
7.5
Description
An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method
Summary dbcve.org
This vulnerability allows an attacker to cause a denial of service in GitLab's integrated Prometheus monitoring system by sending HTTP requests with malformed methods. The vulnerability affects GitLab version 13.7 and later, potentially causing the Prometheus endpoint to become unresponsive.
Mitigation
Upgrade GitLab to the vendor-patched version. If immediate patching is not feasible, implement network-level filtering or Web Application Firewall (WAF) rules to block malformed HTTP method requests to the Prometheus endpoint.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
1.38%
Probability of exploitation in next 30 days
70.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.