PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-22175 GitLab CVE debrief

CVE-2021-22175 is a GitLab server-side request forgery (SSRF) vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. That KEV listing means organizations using GitLab should treat this as a priority remediation item and follow the vendor’s mitigation guidance as soon as possible. The supplied source corpus does not include version ranges, exploitation details, or impact specifics beyond the SSRF classification, so the safest response is to prioritize mitigation based on the KEV status and the official vendor/CVE records.

Vendor
GitLab
Product
GitLab
CVSS
MEDIUM 6.8
CISA KEV
Listed
Original CVE published
2026-02-18
Original CVE updated
2026-02-18
Advisory published
2026-02-18
Advisory updated
2026-02-18

Who should care

GitLab administrators, security operations teams, vulnerability management owners, and cloud service operators running GitLab instances should pay attention to this CVE because it is listed in CISA’s KEV catalog.

Technical summary

The available official source data identifies CVE-2021-22175 as a GitLab server-side request forgery (SSRF) vulnerability. CISA classifies it as a known exploited vulnerability and provides a remediation deadline in the KEV entry. The provided corpus does not include affected version details or a deeper technical write-up, so no further technical claims should be made beyond the official classification and KEV status.

Defensive priority

High. CISA has placed this CVE in the Known Exploited Vulnerabilities catalog, which elevates it above routine backlog items and makes timely mitigation important.

Recommended defensive actions

  • Apply vendor-provided mitigations per official GitLab instructions as soon as possible.
  • Follow CISA BOD 22-01 guidance for cloud services where applicable.
  • If mitigations are unavailable, discontinue use of the product or service as directed by CISA guidance.
  • Review your GitLab deployment inventory and prioritize externally reachable instances.
  • Validate that remediation is completed before the CISA KEV due date in the official entry.

Evidence notes

CISA’s KEV feed lists CVE-2021-22175 as 'GitLab Server-Side Request Forgery (SSRF) Vulnerability' with vendorProject 'GitLab', dateAdded 2026-02-18, and dueDate 2026-03-11. The official CVE and NVD records are linked in the supplied corpus, but the corpus does not include detailed affected-version or exploit-scenario information.

Sources and references

Verified primary and authoritative sources

  • CVE-2021-22175 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-22175

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-22175 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-22175

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.