← Vulnerability feed

Vulnerability record · CVE-2021-39935 · published 13 December 2021

CVE-2021-39935: GitLab CI Lint API server-side request forgery

Gitlab · Gitlab

GitLab CE/EE contains a server-side request forgery flaw in the CI Lint API affecting versions from 10.5 before 14.3.6, 14.4 before 14.4.4, and 14.5 before 14.5.2. Unauthorized external users can make the GitLab server issue requests to attacker-chosen destinations, which matters because the server may reach internal services that are not otherwise exposed.

7.5 CVSS 3.1 High CISA KEV since 3 Feb 2026 EPSS 36% · top 1.6% CWE-918 · Server-side request forgery (SSRF)
7.5CVSS 3.1 base score, v2 5.0
36%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is remotely reachable without authentication, has high confidentiality impact, and is listed in CISA KEV with elevated EPSS, though it is not tied to ransomware.

What it is

GitLab CE/EE contains a server-side request forgery flaw in the CI Lint API affecting versions from 10.5 before 14.3.6, 14.4 before 14.4.4, and 14.5 before 14.5.2. Unauthorized external users can make the GitLab server issue requests to attacker-chosen destinations, which matters because the server may reach internal services that are not otherwise exposed.

Impact

An attacker gains the ability to send requests from the GitLab server to internal or otherwise unreachable systems, with high confidentiality impact per the CVSS vector. There is no integrity or availability impact in the stated vector.

Attack surface

Reached over the network through the CI Lint API; the CVSS vector shows no privileges required and no user interaction, and the description states unauthorized external users can trigger it.

Exploitation

CVE-2021-39935 is listed in CISA KEV with a due date of 2026-02-24, and EPSS shows a 30-day probability of 0.35649 (98.4th percentile), indicating meaningful exploitation activity. No ransomware campaign use is documented.

What to do

  • Upgrade GitLab CE/EE to 14.3.6, 14.4.4, 14.5.2 or later as applicable to your release line.
  • If immediate patching is not possible, restrict or disable external access to the CI Lint API and follow the vendor's mitigation guidance referenced in the CISA KEV entry.
  • Limit outbound network access from GitLab servers so they cannot reach internal metadata services, admin interfaces or other sensitive internal endpoints.
  • Review GitLab instance exposure to the internet and reduce it where the CI Lint API does not need to be publicly reachable.

Detection

  • Monitor GitLab server outbound connections for requests to internal RFC1918 addresses, loopback or cloud metadata endpoints originating from the GitLab process.
  • Review GitLab and reverse proxy logs for CI Lint API requests from unauthenticated or unexpected external sources.
  • Alert on unusual or repeated CI Lint API calls that correlate with outbound connection attempts to non-GitLab destinations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-39935 to the Known Exploited Vulnerabilities catalog on 3 February 2026 as "GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 24 February 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-39935 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed10.0CVE-2021-22205GitLab CE/EE image parser flaw allows unauthenticated remote code executionGitLab CE/EE failed to properly validate image files passed to a file parser, allowing code injection that leads to remote command execution. The fla…KEVEPSS 100%analysed9.8CVE-2023-7028GitLab CE/EE password reset sent to unverified email, enabling account takeoverGitLab CE/EE versions from 16.1 through 16.7 before their fixed releases could deliver account password reset emails to an unverified email address. …KEVEPSS 95%analysed9.8CVE-2021-22175GitLab unauthenticated SSRF via internal webhook requestsGitLab is vulnerable to server-side request forgery when requests to the internal network for webhooks are enabled. The flaw affects all versions sta…KEVEPSS 53%analysed10.0CVE-2020-13300Gitlab incorrect authorization vulnerabilityGitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorizati…EPSS 1.3%10.0CVE-2019-9174Gitlab server-side request forgery (ssrf) vulnerabilityAn issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.EPSS 2.0%10.0CVE-2018-18843Gitlab server-side request forgery (ssrf) vulnerabilityThe Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.EPSS 1.6%9.9CVE-2025-5121Gitlab missing authorization vulnerabilityAn issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check m…EPSS 12%

Source: NIST National Vulnerability Database (record CVE-2021-39935), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.