The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a GitLab server-side request forgery vulnerability, CVE-2021-39935, to its Known Exploited Vulnerabilities (KEV) catalog after observing active exploitation in the wild. The flaw affects GitLab Community Edition and Enterprise Edition and was originally fixed by GitLab in December 2021; it allows unauthorized external users to abuse the CI Lint API (used to validate CI/CD configurations) to trigger server-side requests.
CISA ordered Federal Civilian Executive Branch (FCEB) agencies to remediate under Binding Operational Directive 22-01, setting a patch deadline of February 24, 2026, and urged private-sector organizations to prioritize mitigation or discontinue use if mitigations are unavailable. Reporting highlighted that the SSRF condition can be leveraged to reach otherwise inaccessible internal resources (e.g., internal services/APIs or cloud metadata endpoints) and noted broad internet exposure of GitLab instances (with Shodan tracking tens of thousands of GitLab-fingerprinted systems), increasing the potential attack surface even though specific public campaigns were not detailed.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Under Binding Operational Directive 22-01, CISA directed U.S. federal civilian agencies to patch or mitigate CVE-2021-39935 and set a remediation deadline of 2026-02-24. CISA also urged organizations to apply workarounds such as disabling the CI Lint API and reviewing logs for suspicious activity if immediate patching was not possible.
CISA added the GitLab SSRF vulnerability CVE-2021-39935 to its Known Exploited Vulnerabilities catalog after determining it was being actively exploited in the wild. The agency warned the flaw could be used for internal network scanning, access to cloud metadata services, or interaction with internal APIs.
GitLab patched CVE-2021-39935 in December 2021, addressing a server-side request forgery issue in the CI Lint API affecting Community and Enterprise Edition versions from 10.5 up to 14.3.6, 14.4.4, and 14.5.2 depending on branch. GitLab warned that unauthorized external users could abuse the flaw to make server-side requests.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.