Server-Side Request Forgery (SSRF) vulnerability in GitLab allows unauthenticated attackers to make requests to internal networks when webhook internal network requests are enabled. This affects GitLab instances from version 10.5 through multiple 13.x versions and is actively exploited according to CISA KEV.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2021-06-11
Added to CISA KEV: 2026-02-18 1713 DAYS BETWEEN CVE AND KEV
CVE-2021-22175 is a Server-Side Request Forgery (SSRF) vulnerability affecting GitLab [2].
CVE-2021-22175 is an unauthenticated GitLab SSRF issue tied to the CI Lint API and outbound request settings. See affected versions, fixes, and mitigations. ... CVE-2021-22175 is a GitLab server-side request forgery (SSRF) flaw that can be triggered by an unauthenticated attacker under specific outbโฆ
A server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker. ... Official websites use .gov A .gov website belongs to an official government organization in the United States.
The vulnerability affects GitLab across multiple versions, specifically from 10.5.0 to 13.6.6 for community and enterprise editions, as well as ...