⚠ Actively exploited
Added to CISA KEV on 2026-02-03. Federal agencies required to patch by 2026-02-24. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable..

CVE-2021-39935Server-Side Request Forgery in Gitlab

Severity
7.5HIGHNVD
VulnCheck6.8
EPSS
65.7%
top 1.49%
CISA KEV
KEV
Added 2026-02-03
Due 2026-02-24
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 13
KEV addedFeb 3
Latest updateFeb 4
KEV dueFeb 24
CISA Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

NVDgitlab/gitlab10.5.014.3.6+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=10.5, <14.3.6, >=14.4, <14.4.4, >=14.5, <14.5.2+2
gitlabgitlab/gitlab

🔴Vulnerability Details

3
GHSA
GHSA-22hj-9cx7-p2hw: An issue has been discovered in GitLab CE/EE affecting all versions starting from 102021-12-14
OSV
CVE-2021-39935: An issue has been discovered in GitLab CE/EE affecting all versions starting from 102021-12-13
VulnCheck
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability2021

💥Exploits & PoCs

1
Nuclei
Gitlab CE/EE 10.5 - Server-Side Request Forgery

📋Vendor Advisories

3
CISA
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability2026-02-03
GitLab
CVE-2021-39935: An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, a2021-12-13
Debian
CVE-2021-39935: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions starting fro...2021

🕵️Threat Intelligence

2
Bleepingcomputer
CISA warns of five-year-old GitLab flaw exploited in attacks2026-02-04
Greynoiseio
New SSRF Exploitation Surge Serves as a Reminder of 2019 Capital One Breach2025-03-11