CVE-2020-13354: GitLab

Medium severity, CVSS 4.3. EPSS: 1.4% chance of exploitation in the next 30 days.

A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9.

Affected products

  • GitLab GitLab: from 12.6.0, before 13.3.9 (fixed in 13.3.9)

Published 2020-11-17. Last modified 2026-06-17.