CISA Warns of GitLab Community and Enterprise Editions SSRF Vulnerability Exploited in Attacks
A critical vulnerability in GitLab has been identified and included in the Known Exploited Vulnerabilities (KEV) catalog. This server-side request forgery (SSRF) flaw, tracked as CVE-2021-39935 , is actively being exploited by threat actors in both…
A critical vulnerability in GitLab has been identified and included in the Known Exploited Vulnerabilities (KEV) catalog. This server-side request forgery (SSRF) flaw, tracked as CVE-2021-39935 , is actively being exploited by threat actors in both GitLab Community and Enterprise editions.
The SSRF vulnerability allows unauthorized external attackers to perform server-side requests via the GitLab CI Lint API. Typically used to validate CI/CD configuration files, this API can be exploited by malicious actors to send crafted requests from the GitLab server to internal or external systems, bypassing network security controls and accessing otherwise unreachable internal resources.
Field Details
Product GitLab Community & Enterprise
CVE ID CVE-2021-39935
A critical vulnerability in GitLab has been identified and included in the Known Exploited Vulnerabilities (KEV) catalog.
Type SSRF
Description SSRF flaw via CI Lint API enabling unauthorized server-side requests
CWE CWE-918
Organizations using affected versions of GitLab are at risk, as exploiting this vulnerability could enable threat actors to scan internal networks, access sensitive data from cloud metadata services, or interact with internal APIs lacking proper authentication. The widespread use of GitLab in DevOps environments further amplifies the risk, potentially granting attackers access to critical development infrastructure and source code repositories.
CISA has included CVE-2021-39935 in the KEV catalog as of February 3, 2026, reflecting observance of active exploitation attempts.
Organizations are advised to immediately apply security patches provided by GitLab. If patching is not feasible, vendor-recommended workarounds should be implemented, or the CI Lint API functionality should be temporarily disabled. Reviewing GitLab access logs for suspicious activities, such as unusual API requests or unexpected outbound connections, is also recommended.
Federal agencies under CISA's Binding Operational Directive (BOD) 22-01 must remediate this vulnerability by February 24, 2026.
Based on reporting by Cyber Security News.
