MEDIUM
CVE-2021-39933
CVSS
6.5
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack.
Summary dbcve.org
A regular expression in GitLab used for parsing user input (notes, comments) is susceptible to catastrophic backtracking, enabling attackers to craft malicious input that causes excessive CPU consumption and denial of service through ReDoS (Regular Expression Denial of Service).
Mitigation
Upgrade GitLab to version 14.3.6, 14.4.4, 14.5.2 or later to patch the vulnerable regular expression.
Weakness (CWE)
CWE-1333
EPSS Score
1.42%
Probability of exploitation in next 30 days
71.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.