Server-Side Request Forgery (SSRF) vulnerability in GitLab CI Lint API allows unauthorized external users to perform internal network requests. GitLab instances are commonly internet-facing, making this vulnerability directly exploitable over the network without authentication.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2021-12-13
Added to CISA KEV: 2026-02-03 1513 DAYS BETWEEN CVE AND KEV
CVE-2021-39935 is a Server-Side Request Forgery (SSRF) vulnerability affecting GitLab Community Edition (CE) and Enterprise Edition (EE) [2].
CISA Warns GitLab SSRF Vulnerability Exploit. A critical GitLab vulnerability has been added to the Known Exploited Vulnerabilities (KEV) catalog. Threat actors are actively exploiting a server-side request forgery (SSRF) flaw in GitLab Community and Enterprise editions. The vulnerability, tracked aβ¦
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all ...