πŸ”΄ CVE-2021-39935

Server-Side Request Forgery (SSRF) vulnerability in GitLab CI Lint API allows unauthorized external users to perform internal network requests. GitLab instances are commonly internet-facing, making this vulnerability directly exploitable over the network without authentication.

← Back to Overview
HIGH_RISK
Risk Level
6.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 β€” Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

πŸ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2021-12-13

Added to CISA KEV: 2026-02-03 1513 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

πŸ” Web Intelligence (Kagi Β· 2026-06-04)

CVE-2021-39935 is a Server-Side Request Forgery (SSRF) vulnerability affecting GitLab Community Edition (CE) and Enterprise Edition (EE) [2].

Exploitation and Threat Actor Usage
  • Active Exploitation: The vulnerability is actively exploited in the wild and is included in the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog [1].
  • Targeted Attacks/Ransomware: While it is confirmed as an actively exploited vulnerability in the KEV catalog, specific public attribution to ransomware campaigns or specific targeted threat actor groups is not widely detailed in standard vulnerability databases. However, its presence in the KEV catalog indicates it is a high-priority target for malicious actors [1].
Attack Method and Requirements
  • Method: The flaw is an SSRF vulnerability located in GitLab’s CI Lint API, which is intended to validate CI/CD configuration files [1].
  • Requirements: It allows unauthorized external users to perform server-side requests [2]. It does not typically require user interaction from an authenticated administrator to trigger, as it is accessible to external attackers [1].
Impact
  • Access/Impact: Successful exploitation allows an attacker to force the GitLab server to make unauthorized requests to internal or external resources. This can potentially lead to information disclosure, scanning of internal networks, or interaction with internal services that are otherwise protected from the public internet [1].
Affected Versions and Mitigation
  • Affected Versions: The vulnerability affects the following versions of GitLab CE/EE:
* All versions starting from 10.5 before 14.3.6 [2] * All versions starting from 14.4 before 14.4.4 [2] * All versions starting from 14.5 before 14.5.2 [2]
  • Status: This issue has been patched by GitLab. Organizations running affected versions are strongly advised to upgrade to the patched versions (14.3.6, 14.4.4, 14.5.2, or later) to mitigate the risk [2].

Sources

  1. CISA Warns of GitLab Community and Enterprise Editions SSRF...

    CISA Warns GitLab SSRF Vulnerability Exploit. A critical GitLab vulnerability has been added to the Known Exploited Vulnerabilities (KEV) catalog. Threat actors are actively exploiting a server-side request forgery (SSRF) flaw in GitLab Community and Enterprise editions. The vulnerability, tracked a…

  2. CVE-2021-39935 Detail - NVD

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all ...