{"api_version":"1","generated_at":"2026-07-23T21:15:52+00:00","cve":"CVE-2021-39938","urls":{"html":"https://cve.report/CVE-2021-39938","api":"https://cve.report/api/cve/CVE-2021-39938.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-39938","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-39938"},"summary":{"title":"CVE-2021-39938","description":"A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands","state":"PUBLIC","assigner":"cve@gitlab.com","published_at":"2021-12-13 16:15:00","updated_at":"2021-12-15 18:55:00"},"problem_types":["CWE-400"],"metrics":[],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/344873","name":"https://gitlab.com/gitlab-org/gitlab/-/issues/344873","refsource":"MISC","tags":[],"title":"Not Found","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39938.json","name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39938.json","refsource":"CONFIRM","tags":[],"title":"2021/CVE-2021-39938.json · master · GitLab.org / cves · GitLab","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-39938","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-39938","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"This vulnerability has been discovered internally by the GitLab team","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"39938","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"39938","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-39938","qid":"690733","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for gitlab (b299417a-5725-11ec-a587-001b217b3468)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-39938","ASSIGNER":"cve@gitlab.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"GitLab","product":{"product_data":[{"product_name":"GitLab","version":{"version_data":[{"version_value":">=14.5, <14.5.2"},{"version_value":">=14.4, <14.4.4"},{"version_value":">=8.15, <14.3.6"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Uncontrolled resource consumption in GitLab"}]}]},"references":{"reference_data":[{"name":"https://gitlab.com/gitlab-org/gitlab/-/issues/344873","url":"https://gitlab.com/gitlab-org/gitlab/-/issues/344873","refsource":"MISC"},{"name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39938.json","url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39938.json","refsource":"CONFIRM"}]},"description":{"description_data":[{"lang":"eng","value":"A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands"}]},"impact":{"cvss":{"vectorString":"AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","version":"3.1","baseScore":3,"baseSeverity":"LOW"}},"credit":[{"lang":"eng","value":"This vulnerability has been discovered internally by the GitLab team"}]},"nvd":{"publishedDate":"2021-12-13 16:15:00","lastModifiedDate":"2021-12-15 18:55:00","problem_types":["CWE-400"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.4.0","versionEndExcluding":"14.4.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.5.0","versionEndExcluding":"14.5.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.15.0","versionEndExcluding":"14.3.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.15.0","versionEndExcluding":"14.3.6","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"39938","Ordinal":"215644","Title":"CVE-2021-39938","CVE":"CVE-2021-39938","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"39938","Ordinal":"1","NoteData":"A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands","Type":"Description","Title":null},{"CveYear":"2021","CveId":"39938","Ordinal":"2","NoteData":"2021-12-13","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"39938","Ordinal":"3","NoteData":"2021-12-13","Type":"Other","Title":"Modified"}]}}}