← Vulnerability feed

Vulnerability record · CVE-2021-22205 · published 23 April 2021

CVE-2021-22205: GitLab CE/EE image parser flaw allows unauthenticated remote code execution

Gitlab · Gitlab

GitLab CE/EE failed to properly validate image files passed to a file parser, allowing code injection that leads to remote command execution. The flaw affects all versions starting from 11.9 and is remotely reachable without authentication, making it a severe risk for any exposed GitLab instance.

10.0 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1% CWE-94 · Code injection
10.0CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
11References, 4 tagged exploit
6 Aug 2026Last modified by NVD

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network RCE with CVSS 10, KEV listing, known ransomware use, and near-maximum EPSS make this an urgent patch.

What it is

GitLab CE/EE failed to properly validate image files passed to a file parser, allowing code injection that leads to remote command execution. The flaw affects all versions starting from 11.9 and is remotely reachable without authentication, making it a severe risk for any exposed GitLab instance.

Impact

An unauthenticated attacker can execute arbitrary commands on the GitLab server, leading to full compromise of the host and any data or credentials it holds.

Attack surface

Reachable over the network via the image upload/parsing path with no authentication or user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Listed in CISA KEV with known ransomware campaign use, and EPSS probability is 0.99731 (99.95th percentile); public exploit references are tagged Exploit.

What to do

  • Apply the vendor update for GitLab CE/EE immediately; this is the required KEV action.
  • If patching cannot be done at once, restrict network access to GitLab instances and disable or limit unauthenticated image upload paths.
  • Monitor GitLab releases for the fixed versions covering all releases from 11.9 onward and verify your deployed version.
  • Treat any internet-exposed GitLab instance as compromised until patched and reviewed for signs of command execution.

Detection

  • Hunt for unexpected child processes spawned by GitLab/Rails/ExifTool workers, especially shell or interpreter execution.
  • Review GitLab and web server logs for malformed or unusual image upload requests and parser errors.
  • Monitor for outbound connections or new files/accounts on GitLab hosts consistent with post-exploitation.
  • Correlate host telemetry with the KEV listing and known ransomware activity for this CVE.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-22205 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "GitLab Community and Enterprise Editions Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22205 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed9.8CVE-2023-7028GitLab CE/EE password reset sent to unverified email, enabling account takeoverGitLab CE/EE versions from 16.1 through 16.7 before their fixed releases could deliver account password reset emails to an unverified email address. …KEVEPSS 95%analysed9.8CVE-2021-22175GitLab unauthenticated SSRF via internal webhook requestsGitLab is vulnerable to server-side request forgery when requests to the internal network for webhooks are enabled. The flaw affects all versions sta…KEVEPSS 53%analysed7.5CVE-2021-39935GitLab CI Lint API server-side request forgeryGitLab CE/EE contains a server-side request forgery flaw in the CI Lint API affecting versions from 10.5 before 14.3.6, 14.4 before 14.4.4, and 14.5 …KEVEPSS 36%analysed10.0CVE-2020-13300Gitlab incorrect authorization vulnerabilityGitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorizati…EPSS 1.3%10.0CVE-2019-9174Gitlab server-side request forgery (ssrf) vulnerabilityAn issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.EPSS 2.0%10.0CVE-2018-18843Gitlab server-side request forgery (ssrf) vulnerabilityThe Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.EPSS 1.6%9.9CVE-2025-5121Gitlab missing authorization vulnerabilityAn issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check m…EPSS 12%

Source: NIST National Vulnerability Database (record CVE-2021-22205), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.