Medium severity4.3NVD Advisory· Published Nov 17, 2020· Updated Jun 17, 2026
CVE-2020-13354
CVE-2020-13354
Description
A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 1 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=12.6.0,<13.3.9
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=12.6.0,<13.3.9
- Range: >=12.6, <13.3.9
- Range: >=12.6
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13354.jsonnvdVendor Advisory
- hackerone.com/reports/869875nvdPermissions RequiredThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/220019nvdBroken Link
News mentions
0No linked articles in our index yet.