Vulnerability record · CVE-2023-0921 · published 6 June 2023
CVE-2023-0921: GitLab CE/EE missing length validation in Issue descriptions enables CPU exhaustion
Gitlab · Gitlab
GitLab CE/EE lacks length validation on Issue descriptions submitted via GraphQL, allowing an authenticated user to create an oversized description. Repeatedly requesting that issue saturates CPU usage, degrading availability for other users.
Description
A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Automated analysis
medium priorityCVSS rates it medium (4.3) with only low availability impact, but the very high EPSS score and trivial authenticated trigger warrant prompt patching.
What it is
GitLab CE/EE lacks length validation on Issue descriptions submitted via GraphQL, allowing an authenticated user to create an oversized description. Repeatedly requesting that issue saturates CPU usage, degrading availability for other users.
Impact
An authenticated attacker can cause sustained CPU saturation on the GitLab instance, leading to slow responses or denial of service for legitimate users.
Attack surface
Reachable over the network through the GraphQL API by any authenticated user; no user interaction is required beyond the attacker's own requests.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is very high (0.84438, 99.7th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade GitLab CE/EE to 15.10.8, 15.11.7, or 16.0.2 or later as applicable.
- Enforce request and payload size limits at the reverse proxy or API gateway in front of GitLab.
- Rate-limit GraphQL requests per authenticated user and monitor for abnormal issue description sizes.
- Restrict or audit API tokens and accounts with issue creation permissions.
Detection
- Monitor GraphQL mutation logs for unusually large Issue description payloads.
- Alert on repeated requests to the same large issue within short time windows.
- Track sustained CPU spikes on GitLab application nodes correlated with issue read activity.
- Review audit logs for a single user creating or repeatedly fetching oversized issues.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0921.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/392433 | Issue TrackingVendor Advisory |
| https://hackerone.com/reports/1869839 | Permissions RequiredThird Party Advisory |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0921.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/392433 | Issue TrackingVendor Advisory |
| https://hackerone.com/reports/1869839 | Permissions RequiredThird Party Advisory |
Track CVE-2023-0921 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-0921), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.