@zereight/mcp-gitlab is vulnerable to Regular Expression Denial of Service (ReDoS)
20
Low Risk
Affected versions of this package allow user-controlled regular expression patterns to be processed with insufficient safeguards against catastrophic backtracking, potentially enabling Regular Expression Denial of Service (ReDoS). Although checks attempt to reject overly long patterns and certain nested quantifiers, incomplete validation may still permit crafted patterns that bypass detection. An attacker could supply specially designed regex input that triggers excessive CPU consumption during evaluation, causing application slowdown or service disruption when the pattern is executed against large or complex input.
You are affected if you are using a version that falls within the vulnerable range.
@zereight/mcp-gitlab is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 2.0.0 - 2.0.27.
Upgrade the @zereight/mcp-gitlab library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant