CVE-2021-22175 KEV
6.8
MEDIUM · CVSS 3.1 · EPSS 53.4% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2026-03-11.
Description
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled
Scoring
| CVSS | 6.8 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N |
| EPSS | 53.37% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-918 |
| On CISA KEV | yes — remediate by 2026-03-11 |
| Public exploit | none known |
| Published | 2021-06-11 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | GitLab Server-Side Request Forgery (SSRF) Vulnerability |
|---|---|
| Added | 2026-02-18 |
| Due | 2026-03-11 |
| Vendor / product | GitLab / GitLab |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| gitlab | gitlab |
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22175.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/294178
- https://hackerone.com/reports/1059596
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22175.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/294178
- https://hackerone.com/reports/1059596
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22175
→ the Explorer · watch your stack · NVD