MEDIUM
CVE-2021-22168
CVSS
6.5
Description
A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.
Summary dbcve.org
A regular expression denial of service (ReDoS) vulnerability exists in the NuGet API component of GitLab, affecting all versions starting from 12.8. The vulnerable regex can be triggered by specially crafted input to cause excessive computation, leading to service degradation or unavailability.
Mitigation
Upgrade GitLab to the latest version that includes the patched NuGet API component, or apply the specific security patch for this vulnerability.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
1%
Probability of exploitation in next 30 days
61.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.