VYPR
Unrated severityNVD Advisory· Published Jan 5, 2020· Updated Aug 5, 2024

CVE-2019-19313

CVE-2019-19313

Description

GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

GitLab EE 12.3-12.5, 12.4.3, 12.3.6 allows denial of service via a crafted Markdown link with a character above U+65533, making issue and commit comments unreadable.

Vulnerability

GitLab EE versions 12.3 through 12.5, including 12.4.3 and 12.3.6, are vulnerable to a denial-of-service (DoS) condition in the Issue and Commit comments pages [1]. The bug is triggered by inserting a character with a Unicode code point higher than 0x65533 inside a Markdown link. This causes the server to return HTTP 500 errors when loading discussions, making it impossible to create, edit, or view issues and commits.

Exploitation

An attacker with permission to post comments on a project's issue or commit page can exploit this vulnerability [1]. The attacker crafts a comment containing a Markdown link with a character above U+65533 (e.g., using the provided exploit file). Once the comment is posted, any subsequent request to load the discussions (e.g., discussions.json) fails with a 500 error. This affects not only the issue page but also the Activity page and RSS feed. The attacker does not need any special privileges beyond the ability to comment.

Impact

Successful exploitation results in a denial of service for all users of the affected project [1]. The issue or commit comments become unreadable, and no user can create, edit, or delete comments on that page. The impact is persistent until the malicious comment is removed by an administrator or the server is patched.

Mitigation

GitLab has addressed this vulnerability in a subsequent release [1]. Users should upgrade to GitLab EE version 12.5.1 or later. If upgrading is not immediately possible, administrators can manually remove the malicious comment from the database. No workaround is available within the application itself.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • GitLab/GitLab EEdescription
  • Range: >=12.3, <=12.5, including 12.4.3 and 12.3.6

Patches

3

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.