← Vulnerability feed

Vulnerability record · CVE-2023-0921 · published 6 June 2023

CVE-2023-0921: GitLab CE/EE missing length validation in Issue descriptions enables CPU exhaustion

Gitlab · Gitlab

GitLab CE/EE lacks length validation on Issue descriptions submitted via GraphQL, allowing an authenticated user to create an oversized description. Repeatedly requesting that issue saturates CPU usage, degrading availability for other users.

4.3 CVSS 3.1 Medium EPSS 84% · top 0.3% CWE-770 · Allocation without limits
4.3CVSS 3.1 base score
84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityCVSS rates it medium (4.3) with only low availability impact, but the very high EPSS score and trivial authenticated trigger warrant prompt patching.

What it is

GitLab CE/EE lacks length validation on Issue descriptions submitted via GraphQL, allowing an authenticated user to create an oversized description. Repeatedly requesting that issue saturates CPU usage, degrading availability for other users.

Impact

An authenticated attacker can cause sustained CPU saturation on the GitLab instance, leading to slow responses or denial of service for legitimate users.

Attack surface

Reachable over the network through the GraphQL API by any authenticated user; no user interaction is required beyond the attacker's own requests.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged, but EPSS is very high (0.84438, 99.7th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade GitLab CE/EE to 15.10.8, 15.11.7, or 16.0.2 or later as applicable.
  • Enforce request and payload size limits at the reverse proxy or API gateway in front of GitLab.
  • Rate-limit GraphQL requests per authenticated user and monitor for abnormal issue description sizes.
  • Restrict or audit API tokens and accounts with issue creation permissions.

Detection

  • Monitor GraphQL mutation logs for unusually large Issue description payloads.
  • Alert on repeated requests to the same large issue within short time windows.
  • Track sustained CPU spikes on GitLab application nodes correlated with issue read activity.
  • Review audit logs for a single user creating or repeatedly fetching oversized issues.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-0921 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed10.0CVE-2021-22205GitLab CE/EE image parser flaw allows unauthenticated remote code executionGitLab CE/EE failed to properly validate image files passed to a file parser, allowing code injection that leads to remote command execution. The fla…KEVEPSS 100%analysed9.8CVE-2023-7028GitLab CE/EE password reset sent to unverified email, enabling account takeoverGitLab CE/EE versions from 16.1 through 16.7 before their fixed releases could deliver account password reset emails to an unverified email address. …KEVEPSS 95%analysed9.8CVE-2021-22175GitLab unauthenticated SSRF via internal webhook requestsGitLab is vulnerable to server-side request forgery when requests to the internal network for webhooks are enabled. The flaw affects all versions sta…KEVEPSS 53%analysed7.5CVE-2021-39935GitLab CI Lint API server-side request forgeryGitLab CE/EE contains a server-side request forgery flaw in the CI Lint API affecting versions from 10.5 before 14.3.6, 14.4 before 14.4.4, and 14.5 …KEVEPSS 36%analysed10.0CVE-2020-13300Gitlab incorrect authorization vulnerabilityGitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorizati…EPSS 1.3%10.0CVE-2019-9174Gitlab server-side request forgery (ssrf) vulnerabilityAn issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.EPSS 2.0%10.0CVE-2018-18843Gitlab server-side request forgery (ssrf) vulnerabilityThe Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2023-0921), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.