MEDIUM
CVE-2021-22259
CVSS
6.5
Description
A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.
Summary dbcve.org
GitLab EE versions 12.6 and later contain a denial-of-service vulnerability in the dependencies API endpoint. The lack of pagination controls allows authenticated users to make unbounded requests for dependency data, potentially exhausting server resources or causing performance degradation.
Mitigation
Implement pagination limits on the dependencies API endpoint and upgrade to a patched GitLab version. Rate-limit API requests as an additional defense-in-depth measure.
EPSS Score
1.03%
Probability of exploitation in next 30 days
62.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.