CVE-2021-22175Active Exploitation(gitlab / gitlab)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch gitlab gitlab systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

6.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-11. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-918

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Active exploitation appears in 10 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 6 observed days

What's happening

  • Active exploitation reported across 10 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 9 signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 5 mentions (2026-02-19); latest day: 1
  • 12 total mentions across 6 days

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline12 mentions / 6d
01345Mentions · 2026-02-18: 3Mentions · 2026-02-19: 5Mentions · 2026-02-20: 1Mentions · 2026-02-26: 1Mentions · 2026-03-11: 1Mentions · 2026-04-11: 1Exploit Tool / Code · 2026-03-11: 1Active Exploitation · 2026-02-18: 1Active Exploitation · 2026-02-19: 5Active Exploitation · 2026-02-20: 1Active Exploitation · 2026-02-26: 1Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-04-11: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-02-19: 2Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 5Technical Details · 2026-02-20: 1Technical Details · 2026-02-26: 1Technical Details · 2026-04-11: 102-1802-1902-2002-2603-1104-11
Signal classification4 categories
Active Exploitation
866.7%
Patch
216.7%
Disclosure
18.3%
General
18.3%
Referenced assets31 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-183
Active Exploitation1Disclosure1General1
2026-02-195
Active Exploitation5
2026-02-201
Patch1
2026-02-261
Active Exploitation1
2026-03-111
Patch1
2026-04-111
Active Exploitation1
Full discourse12 posts
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added GitLab vulnerability CVE-2021-22175 & Dell RecoverPoint for VMs vulnerability CVE-2026-22769 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/1bDhLNMVjG

    Post summary

    The tweet announces that CVE-2021-22175 and CVE-2026-22769 are listed in the DHS Known Exploited Vulnerabilities Catalog and recommends applying mitigations to protect organizations.

    12313735.5K
    291.5K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/18追加) 🛡️No.1524 CVE-2021-22175 GitLab Server-Side Request Forgery (SSRF) Vulnerability ============= CVSSスコア: 6.8 (Base) / GitLab Inc. CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N 種別:サーバサイドのリクエストフォージェリ (CWE-918 / GitLab Inc.) 深刻度:注意 ---------------------- 悪用時影響: 事前認証されてない攻撃者により、Webhook の内部ネットワークへのリクエストが有効になっている場合、サーバーサイドリクエスト フォージェリ (SSRF) の脆弱性の影響を受ける恐れがあります。 https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22175.json 🛡️No.1525 CVE-2026-22769 Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability ============= CVSSスコア: 10.0 (Base) / Dell CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 種別:ハードコードされた認証情報の使用 (CWE-798 / Dell) 深刻度:緊急🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートからOSおよび特権レベルで永続的に不正なアクセスが行われる恐れがあります。 https://www.dell.com/support/kbdoc/en-us/000426773/dsa-2026-079 https://www.dell.com/support/kbdoc/en-us/000426742/recoverpoint-for-vms-apply-the-remediation-script-for-dsa https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/18/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA added two CVEs (CVE-2021-22175 and CVE-2026-22769) to its catalog of known exploited vulnerabilities, offering technical details, severity scores, and links to vendor patches or remediation guides.

    0401524.3K
    42.5K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/02/18:Dell RecoverPoint と GitLab の脆弱性を登録 https://iototsecnews.jp/2026/02/19/u-s-cisa-adds-dell-recoverpoint-and-gitlab-flaws-to-its-known-exploited-vulnerabilities-catalog/ 今回、CISA が KEV に追加した脆弱性の原因は、いずれも設計上の基本的な欠陥です。GitLab の脆弱性 CVE-2021-22175 は、内部向け Webhook を通じたリクエスト検証不足により、未認証の攻撃者に内部ネットワークへの侵入を許すものです。もう一方の、Dell RecoverPoint の脆弱性 CVE-2026-22769 は、Tomcat Manager のハードコードされた管理者の認証情報により、未認証の攻撃者に管理機能へのアクセスを許し、WAR ファイルのデプロイを介した root 権限奪取を引き起こすものです。いずれも、入力検証と認証管理の不備が、横展開や永続化の起点となっています。ご利用のチームは、ご注意ください。 #CISA #CVE202122175 #CVE202622769 #Dell #Exploit #GitLab #Government #KEV #RecoverPoint #Vulnerability

    Post summary

    CISA has added CVE‑2021‑22175 and CVE‑2026‑22769 to its KEV catalog, noting that both allow unauthenticated attackers to gain internal network or root access, and urges teams to exercise caution.

    01000129
    485 followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    【リンク集:2月18日〜19日のセキュリティ関連ニュース/記事】 <脆弱性> ・IP電話機Grandstream GXP1600、認証不要のリモートコード実行を許す恐れ(CVE-2026-2329) https://thehackernews.com/2026/02/grandstream-gxp1600-voip-phones-exposed.html ・ハネウェル製監視カメラに認証バイパスの脆弱性(CVE-2026-1670) https://www.bleepingcomputer.com/news/security/critical-infra-honeywell-cctvs-vulnerable-to-auth-bypass-flaw/ ・米CISA、GitLabやDellの仮想環境向けRecoverPointの脆弱性をKEVカタログに追加(CVE-2021-22175、CVE-2026-22769) https://www.cisa.gov/known-exploited-vulnerabilities-catalog ・マイクロソフト、Copilotのバグで機密メールが要約される問題を公表 https://www.bleepingcomputer.com/news/microsoft/microsoft-says-bug-causes-copilot-to-summarize-confidential-emails/ ・Apryse WebViewerとFoxit PDFに脆弱性が複数見つかる アカウント乗っ取りやデータ窃取が可能に https://www.securityweek.com/vulnerabilities-in-popular-pdf-platforms-allowed-account-takeover-data-exfiltration/ <データ侵害/サイバー犯罪> ・フランスの銀行口座120万件のデータにハッカーがアクセス、経済省が認める https://securityaffairs.com/188200/hacking/french-ministry-confirms-data-access-to-1-2-million-bank-accounts.html ・Atlassian Jiraへの信頼を悪用するスパムメール、複数組織を標的に https://www.helpnetsecurity.com/2026/02/18/atlassian-jira-scam-emails/ ・フィンテック企業Figureのデータ侵害、約100万件のアカウントに影響か https://www.bleepingcomputer.com/news/security/data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts/ ・詐欺師がホテルシステムをハッキング 高級客室の宿泊料金を1セントに変更 https://www.theregister.com/2026/02/18/fraudster_hotel_hack_one_cent_luxury_room/ <AI関連> ・Geminiチャットボットを悪用し、存在しない暗号資産を販売 https://www.darkreading.com/endpoint-security/scam-abuses-gemini-chatbots-convince-people-buy-fake-crypto ・AI生成したランダムに見えるパスワード、実は推測可能 https://www.theregister.com/2026/02/18/generating_passwords_with_llms/ <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・米グレンデール在住の男に拘禁5年の判決 ダークネット麻薬密売組織への関与で https://www.bleepingcomputer.com/news/security/glendale-man-gets-5-years-in-prison-for-role-in-darknet-drug-trafficking-operation/ ・マイクロソフトがICCとのメール騒動に関して謝罪 議事録の一部訂正を要請 https://www.theregister.com/2026/02/18/microsoft_asks_uk_parliament_to_correct_record/ ・米テキサス州がTP-Linkを提訴 中国との関連性やセキュリティの問題を指摘 https://www.theregister.com/2026/02/18/texas_sues_tplink_over_china/ <リサーチ/攻撃手法/TTP> ・脅威グループGrayCharlieが法律事務所サイトをハイジャック サプライチェーン攻撃か https://www.recordedfuture.com/research/graycharlie-hijacks-law-firm-sites-suspected-supply-chain-attack ・絵文字に悪意のあるコードを隠蔽する方法 https://sosintel.co.uk/emoji-smuggling-hiding-malicious-code-in-plain-sight/ <政府/政策> ・ポーランド、中国製車両の軍事施設入構を禁止https://therecord.media/poland-bans-chinese-made-cars-from-military-sites <その他> ・オランダ国防相、F-35戦闘機は「iPhoneのように脱獄可能」と発言 https://www.theregister.com/2026/02/18/jailbreak_an_f35/ ・マイクロソフト、フィッシング対策ルールがEメールとTeamsのメッセージを誤検知する問題について説明https://www.bleepingcomputer.com/news/microsoft/microsoft-anti-phishing-rules-mistakenly-blocked-emails-teams-messages/ ・ハッキングカンファレンス「DEF CON」、エプスタイン氏と関係のある3人を追放 https://techcrunch.com/2026/02/18/hacking-conference-def-con-bans-three-people-linked-to-epstein/

    Post summary

    The news roundup highlights several new CVEs, including one listed in CISA’s Known Exploited Vulnerabilities catalog, indicating that the vulnerability is actively being exploited, while also providing some technical details of the flaws.

    00010172
    1.2K followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが2つの既知の脆弱性をカタログに追加 CISA Adds Two Known Exploited Vulnerabilities to Catalog #CISA (Feb 18) CVE-2021-22175 GitLab サーバーサイドリクエストフォージェリ(SSRF)脆弱性 CVE-2026-22769 Dell RecoverPoint for Virtual Machines (RP4VMs) におけるハードコードされた資格情報の使用に関する脆弱性 https://www.cisa.gov/news-events/alerts/2026/02/18/cisa-adds-two-known-exploited-vulnerabilities-catalog

    Post summary

    CISA added two known exploited vulnerabilities to its catalog: a GitLab SSRF flaw and a Dell RecoverPoint hardcoded credential issue, but did not provide exploit details or patches.

    00010200
    4.7K followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [CRITICAL] Active exploitation detected: CVE-2021-22175 Exploit in the wild confirmed for CVE-2021-22175 (CVSS 9.8). GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the i... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    CVE‑2021‑22175, a high‑severity SSRF flaw in GitLab (CVSS 9.8), is confirmed to be actively exploited in the wild.

    0000086
    5.6K followersView on X
  • 404🌐LABS@404LABSx
    Patch

    🚨 ThreatIntel Mar 11: QakBot C2 ONLINE | CobaltStrike certs blacklisted | Russian APT targeting Signal/WhatsApp | PATCH: CVE-2021-22175 (GitLab) DUE TODAY | 300+ malicious URLs active #CyberSecurity #ThreatIntel #CISA

    Post summary

    The tweet highlights that a patch for CVE‑2021‑22175 is due today, while also reporting active exploitation of QakBot C2, blacklisting of CobaltStrike certificates, and Russian APT activity targeting messaging apps.

    0000053
    46 followersView on X
  • David M 🇷🇼🇮🇱💕@SecureComputer0
    Patch

    🚨 GitLab SSRF (CVE-2021-22175) is now on CISA’s KEV list (confirmed exploited in real attacks). Do today: patch GitLab, restrict outbound access, and monitor requests to internal IP ranges. https://www.cisa.gov/news-events/alerts/2026/02/18/cisa-adds-two-known-exploited-vulnerabilities-catalog #GitLab #KEV https://t.co/crZoXsAj4i

    Post summary

    The tweet warns that GitLab SSRF CVE‑2021‑22175 is on CISA’s KEV list and has been exploited in the wild, urging immediate patching, outbound restriction, and monitoring of internal IP requests.

    0000047
    897 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Flags Actively Exploited Dell RecoverPoint & GitLab Bugs in KEV List CISA added GitLab’s SSRF flaw (CVE-2021-22175) and Dell RecoverPoint for VMs hard-coded credentials issue (CVE-2026-22769) to its KEV catalog after evidence of in-the-wild exploitation, urging rapid patching—especially for VMware backup environments where PRC-linked activity reportedly used the Dell zero-day for persistence/lateral movement and malware deployment. This matters because KEV additions signal real exploitation risk and drive hard deadlines for federal agencies (and a strong patch-priority signal for everyone else). 🕷️ Malware: BRICKSTORM / GRIMBOLT / SLAYSTYLE 🎯 Target: US/Federal + Global/Enterprise (VMware backup environments) #️⃣ Category: #Vulnerability #APT #BlueTeam 🔗 URL: https://securityaffairs.com/188243/hacking/u-s-cisa-adds-dell-recoverpoint-and-gitlab-flaws-to-its-known-exploited-vulnerabilities-catalog.html

    Post summary

    CISA added CVE‑2021‑22175 and CVE‑2026‑22769 to its KEV catalog after confirming active exploitation, urging organizations to apply patches immediately.

    0000046
    174 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Active Exploitation

    CISA、2つの既知の悪用された脆弱性をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/02/18/cisa-adds-two-known-exploited-vulnerabilities-catalog CVE-2021-22175 GitLab サーバーサイドリクエストフォージェリ(SSRF)脆弱性 CVE-2026-22769 Dell RecoverPoint for Virtual Machines (RP4VMs) におけるハードコードされた資格情報の使用に関する脆弱性

    Post summary

    CISA has added two known‑exploited CVEs to its catalog—GitLab SSRF (CVE-2021-22175) and hardcoded credentials in Dell RecoverPoint (CVE-2026-22769)—with no details on patches or PoC provided.

    0000047
    44 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2021-22175 - GitLab - GitLab - https://www.redpacketsecurity.com/cve-alert-cve-2021-22175-gitlab-gitlab/ #OSINT #ThreatIntel #CyberSecurity #cve-2021-22175 #gitlab #

    Post summary

    The tweet alerts about CVE-2021-22175 in GitLab but gives no additional details, proof‑of‑concept, exploitation evidence, or mitigation information.

    0000069
    3.5K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 GitLab SSRF leads to Critical Information Disclosure (#CVE-2021-22175) https://dailycve.com/gitlab-ssrf-leads-to-critical-information-disclosure-cve-2021-22175/

    Post summary

    The tweet announces a critical SSRF vulnerability (CVE-2021-22175) in GitLab that can lead to information disclosure, but it does not provide a PoC, exploit details, or patch information.

    0000048
    162 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---

Explore more