CVE-2022-3639

MEDIUM

GitLab 10.8.0-15.1.5, 15.2.0-15.2.3, 15.3.0-15.3.1 - Denial of Service via Branch Creation

Title source: llm
STIX 2.1

Description

A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.

Scores

CVSS v3 4.3
EPSS 0.0015
EPSS Percentile 34.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (1)
gitlab/gitlab 10.8.0 - 15.1.6
Published Oct 21, 2022
Tracked Since Feb 18, 2026