CVE-2024-8124
massUnauthenticated Regular-Expression DoS in GitLab CE/EE via crafted POST request
GitLab CE and EE versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2 contain a denial-of-service flaw classified as inefficient regular expression complexity (CWE-1333). An unauthenticated remote attacker can trigger it by sending a specific, crafted POST request to an affected instance, with no privileges or user interaction required (CVSS AV:N/AC:L/PR:N/UI:N). The impact is limited to availability: the crafted request can consume excessive processing time and degrade or hang the instance (CVSS 7.5 High, with no confidentiality or integrity impact). Any organization running a self-managed GitLab Community Edition or Enterprise Edition instance in those version ranges is affected, while instances running versions older than 16.4 or the patched releases are not. No public proof-of-concept or confirmed in-the-wild exploitation is known and the flaw is not in CISA KEV, but a 40% EPSS score (99th percentile) indicates an elevated likelihood of exploitation attempts within 30 days.
What to do: Upgrade self-managed GitLab CE/EE to 17.1.7, 17.2.5, or 17.3.2, or the latest available release, and verify the running version in the instance's admin interface first. If an immediate upgrade is not possible, restrict unauthenticated network access to the GitLab web/API at the firewall or reverse-proxy layer and apply rate limiting on POST traffic while monitoring for CPU/latency spikes that would indicate DoS attempts. Given the 40% EPSS score, prioritize patching internet-facing instances.
| GitLab CE (Community Edition) | All versions starting from 16.4 prior to 17.1.7; starting from 17.2 prior to 17.2.5; starting from 17.3 prior to 17.3.2 |
| GitLab EE (Enterprise Edition) | All versions starting from 16.4 prior to 17.1.7; starting from 17.2 prior to 17.2.5; starting from 17.3 prior to 17.3.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a specific POST request.
- Vendors
- gitlab
- Products
- gitlab
- Weakness
- CWE-1333
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.