← Back to browse · API

CVE-2023-3364

Severity
HIGH
CVSS
7.5
EPSS
0.44494
Risk score
45.57
CISA KEV
No
PoC
No
Published
2023-08-01
Modified
2025-11-20
First seen
2026-08-07
Aliases
EUVD-2023-44031, GHSA-HF2F-3FP9-M472
Products
GitLab:GitLab 16.1 <16.1.3, GitLab:GitLab 16.2 <16.2.2, GitLab:GitLab 8.14 <16.0.8
Sources
euvd EUVD-2023-44031

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use AutolinkFilter to the preview_markdown endpoint.

References