PatchSiren cyber security CVE debrief
CVE-2021-22175 GitLab CVE debrief
CVE-2021-22175 is a GitLab server-side request forgery (SSRF) vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. That KEV listing means organizations using GitLab should treat this as a priority remediation item and follow the vendor’s mitigation guidance as soon as possible. The supplied source corpus does not include version ranges, exploitation details, or impact specifics beyond the SSRF classification, so the safest response is to prioritize mitigation based on the KEV status and the official vendor/CVE records.
- Vendor
- GitLab
- Product
- GitLab
- CVSS
- MEDIUM 6.8
- CISA KEV
- Listed
- Original CVE published
- 2026-02-18
- Original CVE updated
- 2026-02-18
- Advisory published
- 2026-02-18
- Advisory updated
- 2026-02-18
Who should care
GitLab administrators, security operations teams, vulnerability management owners, and cloud service operators running GitLab instances should pay attention to this CVE because it is listed in CISA’s KEV catalog.
Technical summary
The available official source data identifies CVE-2021-22175 as a GitLab server-side request forgery (SSRF) vulnerability. CISA classifies it as a known exploited vulnerability and provides a remediation deadline in the KEV entry. The provided corpus does not include affected version details or a deeper technical write-up, so no further technical claims should be made beyond the official classification and KEV status.
Defensive priority
High. CISA has placed this CVE in the Known Exploited Vulnerabilities catalog, which elevates it above routine backlog items and makes timely mitigation important.
Recommended defensive actions
- Apply vendor-provided mitigations per official GitLab instructions as soon as possible.
- Follow CISA BOD 22-01 guidance for cloud services where applicable.
- If mitigations are unavailable, discontinue use of the product or service as directed by CISA guidance.
- Review your GitLab deployment inventory and prioritize externally reachable instances.
- Validate that remediation is completed before the CISA KEV due date in the official entry.
Evidence notes
CISA’s KEV feed lists CVE-2021-22175 as 'GitLab Server-Side Request Forgery (SSRF) Vulnerability' with vendorProject 'GitLab', dateAdded 2026-02-18, and dueDate 2026-03-11. The official CVE and NVD records are linked in the supplied corpus, but the corpus does not include detailed affected-version or exploit-scenario information.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-22175 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-22175
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-22175 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-22175
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.