CVE-2021-39938

LOW

Gitlab < 14.3.6 - Denial of Service

Title source: rule
STIX 2.1

Description

A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands

References (2)

Core 2

Scores

CVSS v3 3.1
EPSS 0.0014
EPSS Percentile 33.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-400
Status published
Products (1)
gitlab/gitlab 8.15.0 - 14.3.6 (2 CPE variants)
Published Dec 13, 2021
Tracked Since Feb 18, 2026