CVE-2023-5963

LOW

Gitlab < 16.3.6 - Resource Allocation Without Limits

Title source: rule

Description

An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.

Scores

CVSS v3 3.1
EPSS 0.0001
EPSS Percentile 2.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Classification

CWE
CWE-770
Status published

Affected Products (2)

gitlab/gitlab < 16.3.6
gitlab/gitlab

Timeline

Published Nov 06, 2023
Tracked Since Feb 18, 2026