CVE detail
CVE-2024-2800 — CVE-2024-2800
Published 2024-08-08 · Modified 2026-06-17 · Vendor gitlab · Product gitlab · Source nvd
MEDIUM
severity
CVSS-derived band
0.0067
EPSS probability
exploitation probability, 30d
49.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of service via Regex backtracking.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References