peter bassill · operator
$ cve CVE-2021-39935 JSON

CVE-2021-39935 KEV

6.8
MEDIUM · CVSS 3.1 · EPSS 35.6% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2026-02-24.

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

Scoring

CVSS6.8 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS35.65% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-918
On CISA KEVyes — remediate by 2026-02-24
Public exploitnone known
Published2021-12-13
Last modified2026-06-17

CISA KEV

NameGitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
Added2026-02-03
Due2026-02-24
Vendor / productGitLab / Community and Enterprise Editions
Ransomware usenone reported

Affected (1)

VendorProduct
gitlabgitlab

References

→ the Explorer  ·  watch your stack  ·  NVD