CVE-2021-39938

LOW

GitLab 8.15.0-14.3.5, 14.4.0-14.4.3, 14.5.0-14.5.1 - Denial of Service via Deploy Slash Command Regex

Title source: llm
STIX 2.1

Description

A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands

References (2)

Core 2

Scores

CVSS v3 3.1
EPSS 0.0089
EPSS Percentile 54.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-400
Status published
Products (1)
gitlab/gitlab 8.15.0 - 14.3.6 (2 CPE variants)
Published Dec 13, 2021
Tracked Since Feb 18, 2026