GitLab Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for GitLab products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

6

In CISA KEV

4

Beyond CISA KEV

2

Sensor Observed

0

Virtual Patch Available

0

GitLab KEVs Added by Year

Loading...

6 GitLab KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2021-22175

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions...

Confirmed In CISA 01 Jun 2026
CVE-2021-39935

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before...

Confirmed In CISA 01 Jun 2026
CVE-2021-4191

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with...

High Not in CISA 28 Apr 2025
CVE-2021-22205

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were...

Confirmed In CISA 03 Nov 2021
CVE-2023-7028

Weak Password Recovery Mechanism for Forgotten Password in GitLab

Confirmed In CISA 01 May 2024
CVE-2021-22214

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions...

High Not in CISA 08 Jun 2021

Common Vulnerability Classes (CWE)

  • CWE-918 — Server-Side Request Forgery (SSRF) 3
  • CWE-640 — Weak Password Recovery Mechanism for Forgotten Password 1
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology