Server-Side Request Forgery in GitLab Community and Enterprise Editions via CI Lint API
CISA: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
CVSS 3.1
7.5high
EPSS
36%p98
Published
()
KEV added
AI analysis
CVE-2021-39935 is a server-side request forgery (CWE-918) in GitLab Community Edition and Enterprise Edition that allows unauthorized external users to make the GitLab server issue requests through the CI Lint API. By abusing the server's network position, an attacker can reach internal-only resources such as loopback or private-network services, potentially mapping or accessing internal infrastructure without credentials. All deployments of the affected editions are potentially exposed, with actual risk depending on whether the CI Lint API is reachable by unauthenticated external users. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-03, indicating known exploitation in the wild, though no public proof-of-concept is known and ransomware use is unconfirmed. EPSS estimates a 35.6% probability of exploitation within 30 days (98th percentile).
What to do: Upgrade GitLab CE/EE to the patched release identified in GitLab's security advisory for CVE-2021-39935 (version numbers are not provided in the source data). Until patching is complete, restrict unauthenticated external access to the CI Lint API (e.g., at the reverse proxy or firewall) and review logs for unexpected requests to loopback or internal-network targets originating from CI lint calls. Federal agencies must follow BOD 22-01 remediation timelines following the 2026-02-03 KEV listing; discontinue or isolate use if mitigations are unavailable.
Affected
GitLab Community Edition (CE)
—
GitLab Enterprise Edition (EE)
—
Estimated exposure
largetens of thousands of internet-exposed self-managed GitLab instances; the affected code also runs on GitLab.com SaaS (millions of users) — Public internet scans (e.g., Shodan/Censys) consistently show on the order of tens of thousands of self-managed GitLab instances exposed online, and the same editions power the GitLab.com SaaS platform with a user base in the millions; the…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API
CISA Known Exploited Vulnerability
Affected
GitLab Community and Enterprise Editions
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
GitLab urges self-managed users to immediately patch a maximum-severity path traversal flaw (CVE-2023-2825) enabling unauthenticated arbitrary file reads.
GitLab released patches in CE/EE versions 19.3.2, 19.2.6, and 19.1 for CVE-2023-2825, a maximum-severity path traversal vulnerability that lets unauthenticated attackers read arbitrary files from vulnerable servers under certain conditions. The flaw, reported by researcher s3ntago via HackerOne, stems from improper path confinement and missing authentication enforcement in the repository commits API. GitLab also patched CVE-2026-87719, an insecure deserialization flaw in the GraphQL subscription serializer affecting Enterprise Edition users with Duo Chat access, which could expose credentials and Advanced Search configurations. GitLab.com and Dedicated customers are already protected; the platform has over 30 million registered users and is used by more than 50% of Fortune 100 companies.
CISA added max-severity GitLab CVE-2026-85706 to its exploited-flaws catalog after watchTowr observed probing of unpatched servers.
CISA added CVE-2026-85706, a maximum-severity GitLab flaw caused by missing authentication enforcement and improper path confinement in the repository commits API, to its actively exploited vulnerabilities catalog. Unauthenticated attackers can read credentials, secrets, and arbitrary files from vulnerable servers via a single HTTP request. GitLab patched the issue in CE/EE versions 19.3.2, 19.2.6, and 19.1, and federal agencies have three days to remediate under BOD 26-04. watchTowr reported in-the-wild probes for unpatched GitLab servers, and this is the fourth GitLab vulnerability CISA has tagged as actively exploited since November 2021.