Medium severity6.5NVD Advisory· Published Feb 5, 2025· Updated Jun 17, 2026
CVE-2023-6386
CVE-2023-6386
Description
A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike the GitLab instance resource usage resulting in service degradation.
Affected products
6cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 15.11
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=15.11.0,<16.6.7
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=15.11.0,<16.6.7
- (no CPE)range: from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2
- Range: from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/433147nvdBroken Link
- hackerone.com/reports/2261581nvdPermissions Required
News mentions
1- GitLab Security Release: 16.8.2, 16.7.5, 16.6.7GitLab Security Releases · Feb 7, 2024