LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-39935: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 3, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 24, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-39935 to its Known Exploited Vulnerabilities catalog on Feb 3, 2026, with a federal patch deadline of Feb 24, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.

GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability that allows unauthorized external users to cause the application to issue requests to arbitrary destinations through the CI Lint API. This matters because successful abuse can expose internal services, cloud metadata, or other resources that the GitLab server can reach, increasing the chance of further compromise without direct authentication.

How it works

The weakness is classified as CWE-918, Server-Side Request Forgery. An attacker supplies crafted input to the CI Lint API endpoint; the server then performs an outbound request to the supplied target instead of restricting the destination. The flaw class permits an unauthenticated or low-privileged caller to reach internal hosts or external systems that the GitLab instance itself can contact.

Am I affected? How to find it in your systems

Any deployment of GitLab Community Edition or Enterprise Edition that exposes the CI Lint API is potentially in scope. Inventory all self-hosted GitLab installations and any SaaS tenants where custom runners or CI features are enabled. Confirm the precise versions and configuration settings against the vendor advisory, because the presence of the CI Lint API and its network reach determine exposure.

How to remediate

Apply the vendor-supplied update referenced in the official advisory. After patching, review SSRF-specific hardening for this product class: restrict outbound network access from the GitLab application servers to only required destinations, enforce allow-lists on any URL-handling code paths, and disable or tightly control the CI Lint API if it is not required for business operations.

If you can't patch immediately

Follow the mitigations published in the vendor advisory. For cloud-hosted instances, apply any applicable BOD 22-01 guidance. Where those controls are unavailable, consider network segmentation that prevents the GitLab server from reaching sensitive internal resources, or temporarily disable the affected CI Lint functionality until the update can be installed.

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to unauthorized access and subsequent breaches. Run a free exposure scan of your organization’s email domains against known breach data to determine whether related credentials or tokens already appear in public records.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGitLab · Community and Enterprise Editions
WeaknessCWE-918
Added to CISA KEVFeb 3, 2026
Federal patch deadlineFeb 24, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities