MEDIUM
CVE-2021-39912
CVSS
5.3
Description
A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion.
Summary dbcve.org
A denial of service vulnerability exists in GitLab CE/EE versions 13.7 and later where processing a malformed TIFF image can trigger memory exhaustion, potentially causing the service to become unavailable.
Mitigation
Update GitLab to the patched version (contact GitLab for specific fixed version) or implement temporary image upload restrictions until patching is feasible.
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
1.48%
Probability of exploitation in next 30 days
72.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.