PatchSiren cyber security CVE debrief
CVE-2021-22175 GitLab CVE debrief
CVE-2021-22175 is a GitLab server-side request forgery (SSRF) vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. That KEV listing means organizations using GitLab should treat this as a priority remediation item and follow the vendor’s mitigation guidance as soon as possible. The supplied source corpus does not include version ranges, exploitation details, or impact specifics beyond the SSRF classification, so the safest response is to prioritize mitigation based on the KEV status and the official vendor/CVE records.
- Vendor
- GitLab
- Product
- GitLab
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2026-02-18
- Original CVE updated
- 2026-02-18
- Advisory published
- 2026-02-18
- Advisory updated
- 2026-02-18
Who should care
GitLab administrators, security operations teams, vulnerability management owners, and cloud service operators running GitLab instances should pay attention to this CVE because it is listed in CISA’s KEV catalog.
Technical summary
The available official source data identifies CVE-2021-22175 as a GitLab server-side request forgery (SSRF) vulnerability. CISA classifies it as a known exploited vulnerability and provides a remediation deadline in the KEV entry. The provided corpus does not include affected version details or a deeper technical write-up, so no further technical claims should be made beyond the official classification and KEV status.
Defensive priority
High. CISA has placed this CVE in the Known Exploited Vulnerabilities catalog, which elevates it above routine backlog items and makes timely mitigation important.
Recommended defensive actions
- Apply vendor-provided mitigations per official GitLab instructions as soon as possible.
- Follow CISA BOD 22-01 guidance for cloud services where applicable.
- If mitigations are unavailable, discontinue use of the product or service as directed by CISA guidance.
- Review your GitLab deployment inventory and prioritize externally reachable instances.
- Validate that remediation is completed before the CISA KEV due date in the official entry.
Evidence notes
CISA’s KEV feed lists CVE-2021-22175 as 'GitLab Server-Side Request Forgery (SSRF) Vulnerability' with vendorProject 'GitLab', dateAdded 2026-02-18, and dueDate 2026-03-11. The official CVE and NVD records are linked in the supplied corpus, but the corpus does not include detailed affected-version or exploit-scenario information.
Official resources
-
CVE-2021-22175 CVE record
CVE.org
-
CVE-2021-22175 NVD detail
NVD
-
CISA Known Exploited Vulnerabilities catalog
CISA - Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
-
Source item URL
cisa_kev
Public debrief based only on the supplied official/CISA source corpus and linked authoritative records. Technical specifics are intentionally limited to avoid unsupported claims.