MEDIUM
CVE-2022-1954
CVSS
5.3
Description
A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to make a GitLab instance inaccessible via specially crafted web server response headers
Summary dbcve.org
A Regular Expression Denial of Service (ReDoS) vulnerability in GitLab CE/EE allows specially crafted web server response headers to trigger inefficient regex processing, causing excessive CPU consumption that renders the GitLab instance inaccessible.
Mitigation
Upgrade GitLab to version 14.10.5, 15.0.4, 15.1.1 or later to patch the vulnerable regex pattern in header processing.
Weakness (CWE)
CWE-1333
EPSS Score
1.03%
Probability of exploitation in next 30 days
62.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.