GitLab Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for GitLab products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
6
In CISA KEV
4
Beyond CISA KEV
2
Sensor Observed
0
Virtual Patch Available
0
GitLab KEVs Added by Year
6 GitLab KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2021-22175
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions... |
GitLab | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2021-39935
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before... |
GitLab | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2021-4191
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with... |
GitLab | High | Not in CISA | 28 Apr 2025 |
|
CVE-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were... |
GitLab | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2023-7028
Weak Password Recovery Mechanism for Forgotten Password in GitLab |
GitLab | Confirmed | In CISA | 01 May 2024 |
|
CVE-2021-22214
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions... |
GitLab | High | Not in CISA | 08 Jun 2021 |
Common Vulnerability Classes (CWE)
- CWE-918 — Server-Side Request Forgery (SSRF) 3
- CWE-640 — Weak Password Recovery Mechanism for Forgotten Password 1
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology