CVE-2021-22166: GitLab

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method

Affected products

  • GitLab GitLab: from 13.7.0, before 13.7.2 (fixed in 13.7.2)

Published 2021-01-15. Last modified 2026-06-17.