CVE-2021-39935Active Exploitation(gitlab / gitlab)

HIGHCVSS 7.5 · HIGHCISA KEV

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch gitlab gitlab systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-24. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-918

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Active exploitation appears in 18 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 23 mentions across 5 observed days

What's happening

  • Active exploitation reported across 18 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 21 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 9 mentions (2026-02-04); latest day: 3
  • 23 total mentions across 5 days

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline23 mentions / 5d
02579Mentions · 2026-02-03: 5Mentions · 2026-02-04: 9Mentions · 2026-02-05: 3Mentions · 2026-02-11: 3Mentions · 2026-02-12: 3PoC Mentioned / Linked · 2026-02-04: 1PoC Mentioned / Linked · 2026-02-05: 1Exploit Tool / Code · 2026-02-04: 1Exploit Tool / Code · 2026-02-05: 1Active Exploitation · 2026-02-03: 4Active Exploitation · 2026-02-04: 7Active Exploitation · 2026-02-05: 3Active Exploitation · 2026-02-11: 3Active Exploitation · 2026-02-12: 1Patch / Workaround · 2026-02-03: 2Patch / Workaround · 2026-02-04: 6Patch / Workaround · 2026-02-05: 2Patch / Workaround · 2026-02-11: 1Technical Details · 2026-02-03: 5Technical Details · 2026-02-04: 8Technical Details · 2026-02-05: 2Technical Details · 2026-02-11: 3Technical Details · 2026-02-12: 302-0302-0402-0502-1102-12
Signal classification4 categories
Active Exploitation
1669.6%
Disclosure
417.4%
Patch
28.7%
General
14.3%
Referenced assets40 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-035
Active Exploitation3Disclosure2
2026-02-049
Active Exploitation7General1Patch1
2026-02-053
Active Exploitation2Patch1
2026-02-113
Active Exploitation3
2026-02-123
Active Exploitation1Disclosure2
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    ‼️ CISA has added 4 vulnerabilities to the KEV Catalog https://darkwebinformer.com/cisa-kev-catalog/ CVE-2025-40551: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability CVE-2019-19006: Sangoma FreePBX Improper Authentication Vulnerability CVE-2025-64328: Sangoma FreePBX OS Command Injection Vulnerability CVE-2021-39935: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

    Post summary

    The post announces that CISA has added four CVEs to the KEV catalog, indicating they are being exploited in the wild, but provides no PoC, exploit code, patches, or false‑positive assertions.

    1401863.7K
    164.9K followersView on X
  • Criminal IP@CriminalIP_US
    Active Exploitation

    🦊 CVE-2021-39935 | GitLab CI Lint API SSRF Added to CISA KEV in Feb 2026 after active exploitation was confirmed. This SSRF flaw enables unauthenticated attackers to trigger server-side requests and probe internal resources via exposed GitLab instances. 🔍 Criminal IP: • 71K+ externally identifiable GitLab assets • 311 web-exposed instances Unpatched GitLab instances remain externally accessible, highlighting the need to continuously identify exposed assets using external visibility. 👉 Full technical analysis: https://www.criminalip.io/knowledge-hub/blog/32679 #GitLab #KEV #SSRF #AttackSurface

    Post summary

    CVE‑2021‑39935 is a GitLab CI Lint API SSRF vulnerability that has been actively exploited, confirmed by its inclusion in the CISA KEV. The flaw permits unauthenticated attackers to make internal server requests, and unpatched instances remain exposed.

    02151922
    4.8K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/3追加) 🛡️No.1503 CVE-2025-40551 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability ============= CVSSスコア: 9.8 (Base) / SolarWinds CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:信頼できないデータのデシリアライゼーション (CWE-502 / SolarWinds) 深刻度:深刻🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートからホストマシン上でコマンドを実行される恐れがあります。 https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40551 🛡️No.1504 CVE-2019-19006 Sangoma FreePBX Improper Authentication Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:不適切な認証 (CWE-287 / CISA-ADP) 深刻度:深刻🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、パスワード認証を回避し、FreePBX管理者が提供するサービスにアクセスされる恐れがあります。 https://iki.freepbx.org/display/FOP/2019-11-20%2BRemote%2BAdmin%2BAuthentication%2BBypass 🛡️No.1505 CVE-2025-64328 Sangoma FreePBX OS Command Injection Vulnerability ============= CVSSスコア: 8.6 (Base) / GitHub, Inc. CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 種別:OSコマンドインジェクション (CWE-78 / GitHub, Inc.) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、testconnection -> check_ssh_connect()関数を介してコマンドインジェクションをされる恐れがあります。この脆弱性を利用して、asteriskユーザーとしてシステムへのリモートアクセスを取得される可能性があります。 https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw 🛡️No.1506 CVE-2021-39935 GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability ============= CVSSスコア: 6.8 (Base) / GitHub, Inc. CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N 種別:サーバサイドのリクエストフォージェリ (CWE-918 / GitHub, Inc.) 深刻度:注意 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、CI Lint API を介してサーバーサイドリクエストを実行される恐れがあります。 https://about.gitlab.com/releases/2021/12/06/security-release-gitlab-14-5-2-released/ CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/03/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA has confirmed that four CVEs are actively exploited and added them to the KEV catalog, providing high CVSS scores and vendor advisory links that include patch information.

    010604.0K
    42.5K followersView on X
  • Clandestine@akaclandestine
    Disclosure

    CVE-2021-39935: GitLab CI Lint API Server-Side Request Forgery Vulnerability | Criminal IP https://www.criminalip.io/knowledge-hub

    Post summary

    A new vulnerability (CVE‑2021‑39935) affecting GitLab CI Lint API via Server‑Side Request Forgery has been disclosed, with a reference link to Criminal IP for additional context.

    01040860
    54.8K followersView on X
  • hiro_@papa_anniekey
    Active Exploitation

    KEV追加 CVE-2019-19006 Sangoma FreePBX CVE-2021-39935 GitLab Community and Enterprise Editions CVE-2025-40551 SolarWinds Web Help Desk CVE-2025-64328 Sangoma FreePBX

    Post summary

    The note lists several CVEs added to KEV, indicating they are known to be exploited, but offers no further technical or patch details.

    00041681
    6.0K followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    【リンク集:2月4日〜5日のセキュリティ関連ニュース/記事】 <脆弱性> ・米CISA、VMware ESXiの脆弱性がランサムウェア攻撃に悪用されていると警告(CVE-2025-22225) https://www.bleepingcomputer.com/news/security/cisa-vmware-esxi-flaw-now-exploited-in-ransomware-attacks/ ・React2Shellを悪用した攻撃が進行中、クリプトマイナーとリバースシェルを拡散(CVE-2025-55182) https://www.securityweek.com/cryptominers-reverse-shells-dropped-in-recent-react2shell-attacks/ ・Google Lookerに複数の重大な脆弱性、セルフホスト型環境が危険にさらされる(CVE-2025-12743) https://www.helpnetsecurity.com/2026/02/04/google-looker-vulnerabilities-cve-2025-12743/ ・5年前のGitLabの脆弱性が攻撃に悪用される CISAが警告(CVE-2021-39935) https://www.bleepingcomputer.com/news/security/cisa-warns-of-five-year-old-gitlab-flaw-exploited-in-attacks/ ・n8nの重大な脆弱性とエクスプロイトが公開される(CVE-2026-25049) https://www.bleepingcomputer.com/news/security/critical-n8n-flaws-disclosed-along-with-public-exploits/ <マルウェア・その他脅威> ・EDRキラー、EnCaseの署名付きカーネルドライバーを使用してセキュリティを無効化 https://www.bleepingcomputer.com/news/security/edr-killer-tool-uses-signed-kernel-driver-from-forensic-software/ <ランサムウェア> ・ランサムウェアグループ「DragonForce」、カルテルモデル推進で「ゴッドファーザー」さながらに https://www.darkreading.com/cyber-risk/ransomware-gang-full-godfather-cartel ・Nitrogenランサムウェアは実行犯でも復号不可能 身代金支払いは無駄 https://www.theregister.com/2026/02/04/nitrogen_ransomware_broken_decryptor/ <データ侵害/サイバー犯罪> ・大規模な情報漏洩は事実か? メキシコ政府は機微なデータの漏洩を否認 https://www.darkreading.com/cyberattacks-data-breaches/big-breach-or-nada-de-nada-mexican-govt-faces-leak-allegations ・AIを使ったクラウド侵害、公開状態のAWS認証情報から8分で管理者権限を獲得 https://hackread.com/8-minute-takeover-ai-hijack-cloud-access/ ・ShinyHunters、米ハーバード大とペンシルベニア大の内部情報とみられるデータを公開 https://techcrunch.com/2026/02/04/hackers-publish-personal-information-stolen-during-harvard-upenn-data-breaches/ ・ハッカーがnginxサーバーを侵害、ユーザートラフィックをリダイレクト https://www.bleepingcomputer.com/news/security/hackers-compromise-nginx-servers-to-redirect-user-traffic/ <サイバー戦/APT/国家型アクター/地政学関連> ・欧州議会議員、ITサービスの米国依存に警鐘 「EUはマイクロソフトで動いている」 https://www.theregister.com/2026/02/04/eu_foss_fears/ ・ロシアの偵察衛星、EUの複数の通信衛星を傍受 https://arstechnica.com/space/2026/02/russian-spy-satellites-have-intercepted-eu-communications-satellites/ ・米国が2025年にサイバー兵器を攻撃に使用 イランの防空網を混乱させる目的で https://therecord.media/iran-nuclear-cyber-strikes-us ・中国のAmaranth-Dragon、偵察活動でWinRARの脆弱性を悪用(CVE-2025-8088) https://thehackernews.com/2026/02/china-linked-amaranth-dragon-exploits.html <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・ダークウェブの麻薬市場「Incognito Market」の運営者に拘禁30年の判決 https://www.bleepingcomputer.com/news/security/taiwanese-man-gets-30-years-for-operating-dark-web-drug-market/ <リサーチ/攻撃手法/TTP> ・Windowsのスクリーンセーバーファイル、攻撃者がマルウェアやRMMツールの配布に利用 https://www.darkreading.com/application-security/attackers-use-screensavers-drop-malware-rmm-tools <政府/政策> ・エストニア政府、マイクロソフトへ移行しつつも欧州の代替サービスを模索中 https://www.theregister.com/2026/02/04/estonia_hedges_its_bets_on/ ・米上院議員、ICEデモ参加者に関するデータベースの有無を政府に問う https://arstechnica.com/tech-policy/2026/02/capture-it-all-ice-urged-to-explain-memo-about-collecting-info-on-protesters/ <その他> ・マイクロソフト、Windows 11にネイティブなSysmon機能を導入予定 https://www.bleepingcomputer.com/news/microsoft/microsoft-rolls-out-native-windows-11-sysmon-security-monitoring/

    Post summary

    The text reports that multiple CVEs—including those in VMware ESXi, React2Shell, Google Looker, GitLab, n8n, and WinRAR—are being actively exploited, with some exploits publicly disclosed but no patches or mitigations mentioned.

    01020353
    1.2K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/02/03:SolarWinds Web Help Desk/GitLab/Sangoma FreePBX の脆弱性を登録 https://iototsecnews.jp/2026/02/04/u-s-cisa-adds-solarwinds-web-help-desk-sangoma-freepbx-and-gitlab-flaws-to-its-known-exploited-vulnerabilities-catalog/ CISA KEV に、SolarWinds Web Help Desk/GitLab/Sangoma FreePBX の脆弱性が登録されました。1 つ目の SolarWinds の CVE-2025-40551 は、プログラムがデータを取り込む際の検証不足により、悪意ある命令を実行してしまう問題があります。2 つ目の GitLab の CVE-2021-39935 は、外部からの不正なリクエストを、サーバが内部向けに送信してしまうという、設定の不備に起因するものです。また、Sangoma FreePBX では、ログイン画面を素通りできてしまう認証の脆弱性 CVE-2019-19006 と、管理操作の裏側でOSへの直接命令が紛れ込む脆弱性 CVE-2025-64328 が悪用されています。これらの脆弱性は、いずれも攻撃者に対してサーバのコントロールを許し得るものであり、実際に悪用が確認されたことで、CISA が警告を発する事態となっています。 #CISA #CVE201919006 #CVE202139935 #CVE202540551 #CVE202564328 #Exploit #FreePBX #GitLab #Government #KEV #SolarWinds #Vulnerability

    Post summary

    CISA KEV announces that CVEs for SolarWinds Web Help Desk, GitLab, and Sangoma FreePBX have been actively exploited, granting attackers server control, with technical details provided but no patch information.

    01000150
    483 followersView on X
  • Criminal IP Japan@CriminalIP_JP
    Active Exploitation

    🦊 CVE-2021-39935 | #GitLab CI Lint API #SSRF​ 2026年2月、未パッチかつインターネットに露出した GitLab インスタンスでの実際の悪用が確認され、CISA は CVE-2021-39935 を KEV カタログに追加しました。​ 🔍 Criminal IP の観測結果​ ・外部から識別可能な GitLab 資産:71,069 件​ ・Web ポート(80/443)が直接露出したインスタンス:311 件​ CI/CD 環境は、トークン・キー・レジストリ認証情報が集中する高価値ターゲットです。​ SSRF を起点に、内部ネットワークのスキャン → 認証情報の取得 → 横展開へと発展する可能性があります。​ ​「パッチ適用の有無」だけでなく、テスト環境や PoC、放置されたインスタンスを含め、外部から到達可能な GitLab が残っていないかを確認することが重要です。​ 👉 ブログを確認​ https://www.criminalip.io/ja/knowledge-hub/blog/8003​ #サイバーセキュリティ #KEV

    Post summary

    The post reports confirmed active exploitation of CVE-2021-39935 on exposed GitLab instances, highlighting the SSRF risk and urging patch verification and environment scans.

    00010281
    1.4K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    CISA orders U.S. federal agencies to patch a 5-year-old GitLab SSRF vulnerability (CVE-2021-39935) actively exploited in attacks. Patch issued Dec 2021; deadline set under BOD 22-01. #GitLabFlaw #ServerSideRequest #UnitedStates https://ift.tt/sDmzUAO

    Post summary

    CISA directed U.S. federal agencies to apply the December 2021 patch for the CVE‑2021‑39935 GitLab SSRF vulnerability, citing active exploitation and setting a deadline under BOD 22‑01.

    00010197
    3.6K followersView on X
  • キタきつね@foxbook
    Disclosure

    CISAが4つの既知の脆弱性をカタログに追加 CISA Adds Four Known Exploited Vulnerabilities to Catalog #CISA (Feb 3) CVE-2019-19006 Sangoma FreePBX の不適切な認証の脆弱性 CVE-2021-39935 GitLab Community および Enterprise エディションのサーバーサイドリクエストフォージェリ (SSRF) 脆弱性 CVE-2025-40551 SolarWinds Webヘルプデスクにおける信頼できないデータのデシリアライゼーションの脆弱性 CVE-2025-64328 Sangoma FreePBX OS コマンドインジェクション脆弱性 https://www.cisa.gov/news-events/alerts/2026/02/03/cisa-adds-four-known-exploited-vulnerabilities-catalog

    Post summary

    The announcement notes that CISA has added four previously known exploited vulnerabilities to its catalog, listing their brief technical details without providing PoC, exploit code, patches, or mitigation information.

    00010297
    4.7K followersView on X
  • ‘BugBounty Writeups’@bbwriteups
    Disclosure

    "GitLab CI Lint API Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021–39935)" by Criminal IP #BugBounty #Cybersecurity #Hacking #InfoSec https://osintteam.blog/gitlab-ci-lint-api-server-side-request-forgery-ssrf-vulnerability-cve-2021-39935-864527d9baaf

    Post summary

    The post announces the discovery of an SSRF vulnerability in GitLab CI Lint API (CVE-2021-39935), providing basic technical details but no PoC, exploit, patch, or evidence of active exploitation.

    0000075
    476 followersView on X
  • Criminal IP Korea@CriminalIP_KR
    Active Exploitation

    🔥 GitLab SSRF 취약점 재점화 | CVE-2021-39935​ 2021년에 패치된 GitLab SSRF 취약점이 2026년 2월, CISA KEV에 추가되며 실제 악용이 다시 확인됐습니다.​ 🔍 Criminal IP 기준​ • 외부 식별 가능한 GitLab 자산 71,069건​ • 웹 포트(80/443) 직접 노출된 인스턴스 311건​ CI/CD 환경은 토큰·키·레지스트리 자격증명이 집중된 고가치 표적입니다. SSRF 하나로 내부망 스캔 → 자격증명 탈취 → 측면 이동까지 이어질 수 있습니다.​ ​ 대응 방안:​ ✔️ 패치 적용​ ✔️ CI Lint API 접근 통제​ ✔️ 테스트·임시 GitLab 인스턴스 외부 노출 점검 필수​ “취약한가”보다 “외부에서 보이는가”가 먼저입니다.​ 👉 전체 분석 바로 확인하기​ https://www.criminalip.io/ko/knowledge-hub/blog/32709​ #GitLab #KEV #사이버보안 #위협인텔리전스

    Post summary

    The GitLab SSRF flaw (CVE‑2021‑39935) has resurfaced with active exploitation confirmed; patching and access controls are recommended.

    00000155
    687 followersView on X
  • Rory J Bernier@RoryCrave
    Active Exploitation

    🚨 CISA added 4 actively exploited vulns to its KEV list: SolarWinds Web Help Desk RCE (CVE-2025-40551), GitLab SSRF (CVE-2021-39935) & 2 Sangoma FreePBX flaws. Patch now. https://www.perplexity.ai/page/cisa-adds-solarwinds-gitlab-fl-Es.eerBlTKy_R0jmdAx_mg

    Post summary

    CISA has listed four CVEs as actively exploited in the wild, including SolarWinds Web Help Desk RCE and GitLab SSRF, and urges immediate patching.

    0000089
    3.0K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Active Exploitation

    CISAが4つの既知の脆弱性をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/02/03/cisa-adds-four-known-exploited-vulnerabilities-catalog CVE-2019-19006  Sangoma FreePBX の不適切な認証の脆弱性 CVE-2021-39935  GitLab Community および Enterprise エディションのサーバーサイドリクエストフォージェリ (SSRF) 脆弱性 他2件

    Post summary

    CISA has added four known exploited vulnerabilities—CVE‑2019‑19006 and CVE‑2021‑39935—to its catalog, indicating they are being exploited in the wild.

    00000110
    45 followersView on X
  • Ostorlab@OstorlabSec
    Active Exploitation

    🚨 CVE-2021-39935: GitLab CI Lint API SSRF Alert 🚨 GitLab An unauthenticated server-side request forgery vulnerability has been disclosed in GitLab CE and EE, allowing attackers to coerce the GitLab server into making arbitrary HTTP requests to internal services and cloud metadata endpoints. Active exploitation is confirmed, and a public proof of concept is available. Risk Severity: Critical. Listed in CISA KEV. Public exploit available. Unauthenticated SSRF in a privileged DevOps platform with broad network access. Impact: Unauthenticated SSRF from an internet-facing endpoint. Access to internal services and administrative interfaces. Cloud credential theft via metadata services. Internal network mapping and reconnaissance. Credential harvesting enabling lateral movement and full infrastructure compromise. Root Cause: CWE-918, Server-Side Request Forgery. GitLab CI Lint API fails to validate user-controlled remote URLs when resolving external CI configuration includes. Outbound requests bypass URL denylist protections during lint processing. Attackers can: Submit malicious CI configurations to the CI Lint API. Force GitLab to fetch internal or cloud metadata URLs. Exfiltrate responses via lint output and error messages. Abuse GitLab’s trusted network position to bypass perimeter controls. Are You Affected? Vulnerable. GitLab CE and EE versions 10.5 through 14.3.5, 14.4 through 14.4.3, and 14.5 through 14.5.1. Fixed. GitLab versions 14.3.6, 14.4.4, 14.5.2, and later releases in each branch. Immediate Action Required: Update GitLab immediately to a fixed version. Restrict outbound network access from GitLab servers, especially to cloud metadata endpoints. Deploy WAF rules to monitor and limit unauthenticated access to the CI Lint API. Hunt logs for suspicious CI Lint API usage and rotate any exposed cloud credentials. SSRF in DevOps tooling turns CI into an internal attack proxy. Patch now or assume internal exposure. 🛡️ #ostorlabCVE

    Post summary

    CVE‑2021‑39935 is a critical unauthenticated SSRF vulnerability in GitLab CI Lint API, actively exploited with a publicly available PoC and exploit; patches are released and should be applied immediately.

    0000092
    582 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA flags actively exploited GitLab SSRF bug (CVE-2021-39935) — patch deadline set for Feb 24 CISA added CVE-2021-39935 (GitLab CI Lint API SSRF) to the KEV catalog after observing in-the-wild exploitation, warning it can let unauthorized external users force server-side requests that aid internal recon and access to sensitive endpoints. Federal agencies must remediate by February 24, 2026, and private-sector orgs running exposed GitLab instances should patch immediately and hunt for abnormal CI Lint API abuse/outbound egress. 🎯 Target: Global/DevOps (GitLab CE/EE) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.bleepingcomputer.com/news/security/cisa-warns-of-five-year-old-gitlab-flaw-exploited-in-attacks/

    Post summary

    CISA reports CVE-2021-39935 is actively exploited in the wild, urges patching by February 24, 2026, and warns of potential internal recon via SSRF.

    0000061
    192 followersView on X
  • Engr. Abubakar Mundir@AbubakarMundir
    Patch

    GitLab patched this server-side request forgery (SSRF) flaw (tracked as CVE-2021-39935) in December 2021, saying it could allow unauthenticated attackers with no privileges to access the CI Lint API, which is used to simulate pipelines and validate CI/CD configurations.

    Post summary

    GitLab patched the SSRF vulnerability CVE-2021-39935 in December 2021, which could allow unauthenticated attackers to access the CI Lint API.

    0000040
    725 followersView on X
  • The DefendOps Diaries@DefendOpsHQ
    General

    Thousands of companies are still exposed to a GitLab bug from 2021 that lets hackers break in without even logging on. Why are so many critical systems still unpatched after five years? https://thedefendopsdiaries.com/a-five-year-old-gitlab-flaw-resurfaces-cve-2021-39935-and-the-ongoing-challenge-of-patch-management/

    Post summary

    The post stresses that many organizations remain exposed to the long‑standing GitLab CVE‑2021‑39935, emphasizing ongoing patch‑management challenges.

    0000046
    29 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA flags actively exploited GitLab SSRF bug: CI Lint API can be turned into an internal scanner CISA added CVE-2021-39935 to its KEV after observing active exploitation: attackers can abuse GitLab’s CI Lint API to trigger server-side requests (SSRF), enabling internal network probing and access to sensitive endpoints (e.g., metadata services) from the GitLab host. Patch immediately (or disable/mitigate CI Lint API) and review logs for anomalous CI Lint requests and unexpected outbound connections from GitLab. 🎯 Target: Global/DevOps (GitLab CE/EE) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/cisa-warns-gitlab-ssrf-vulnerability-exploit/

    Post summary

    CISA reports that CVE-2021-39935 is actively exploited via a GitLab SSRF in the CI Lint API, urging users to patch or disable the feature and monitor for abnormal outbound traffic.

    0000058
    192 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA flags actively exploited SolarWinds Web Help Desk RCE (CVE-2025-40551) and adds more flaws to KEV CISA added SolarWinds Web Help Desk’s unauthenticated deserialization RCE (CVE-2025-40551, CVSS 9.8) to the Known Exploited Vulnerabilities catalog, noting active exploitation and urging immediate upgrade to WHD 2026.1. KEV also added FreePBX (CVE-2019-19006, CVE-2025-64328) and GitLab SSRF (CVE-2021-39935), with federal remediation deadlines of Feb 6 and Feb 24, 2026. 🎯 Target: Global/IT Service Management & VoIP #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://thehackernews.com/2026/02/cisa-adds-actively-exploited-solarwinds.html

    Post summary

    CISA reports SolarWinds Web Help Desk RCE (CVE‑2025‑40551) is actively exploited and urges an immediate upgrade to version 2026.1.

    0000036
    192 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---

Explore more