Home

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use ProjectReferenceFilter to the preview_markdown endpoint.

PUBLISHED Reserved 2023-07-28 | Published 2023-08-02 | Updated 2026-04-27 | Assigner GitLab




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-1333: Inefficient Regular Expression Complexity

Product status

Default status
unaffected

9.3 (semver) before 16.0.8
affected

16.1 (semver) before 16.1.3
affected

16.2 (semver) before 16.2.2
affected

Credits

Thanks [ryhmnlfj](https://hackerone.com/ryhmnlfj) for reporting this vulnerability through our HackerOne bug bounty program finder

References

gitlab.com/gitlab-org/gitlab/-/issues/416225 (GitLab Issue #416225) issue-tracking

hackerone.com/reports/1963255 (HackerOne Bug Bounty Report #1963255) technical-description exploit

gitlab.com/gitlab-org/gitlab/-/issues/416225 (GitLab Issue #416225) issue-tracking permissions-required

hackerone.com/reports/1963255 (HackerOne Bug Bounty Report #1963255) technical-description exploit permissions-required

cve.org (CVE-2023-3994)

nvd.nist.gov (CVE-2023-3994)

Download JSON