PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-22175 GitLab CVE debrief

CVE-2021-22175 is a GitLab server-side request forgery (SSRF) vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. That KEV listing means organizations using GitLab should treat this as a priority remediation item and follow the vendor’s mitigation guidance as soon as possible. The supplied source corpus does not include version ranges, exploitation details, or impact specifics beyond the SSRF classification, so the safest response is to prioritize mitigation based on the KEV status and the official vendor/CVE records.

Vendor
GitLab
Product
GitLab
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2026-02-18
Original CVE updated
2026-02-18
Advisory published
2026-02-18
Advisory updated
2026-02-18

Who should care

GitLab administrators, security operations teams, vulnerability management owners, and cloud service operators running GitLab instances should pay attention to this CVE because it is listed in CISA’s KEV catalog.

Technical summary

The available official source data identifies CVE-2021-22175 as a GitLab server-side request forgery (SSRF) vulnerability. CISA classifies it as a known exploited vulnerability and provides a remediation deadline in the KEV entry. The provided corpus does not include affected version details or a deeper technical write-up, so no further technical claims should be made beyond the official classification and KEV status.

Defensive priority

High. CISA has placed this CVE in the Known Exploited Vulnerabilities catalog, which elevates it above routine backlog items and makes timely mitigation important.

Recommended defensive actions

  • Apply vendor-provided mitigations per official GitLab instructions as soon as possible.
  • Follow CISA BOD 22-01 guidance for cloud services where applicable.
  • If mitigations are unavailable, discontinue use of the product or service as directed by CISA guidance.
  • Review your GitLab deployment inventory and prioritize externally reachable instances.
  • Validate that remediation is completed before the CISA KEV due date in the official entry.

Evidence notes

CISA’s KEV feed lists CVE-2021-22175 as 'GitLab Server-Side Request Forgery (SSRF) Vulnerability' with vendorProject 'GitLab', dateAdded 2026-02-18, and dueDate 2026-03-11. The official CVE and NVD records are linked in the supplied corpus, but the corpus does not include detailed affected-version or exploit-scenario information.

Official resources

Public debrief based only on the supplied official/CISA source corpus and linked authoritative records. Technical specifics are intentionally limited to avoid unsupported claims.