s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2021-22175

📛 CVE Title

Gitlab Gitlab: CVE-2021-22175: Server-side request forgery (ssrf) in GitLab

Description

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

Overview

State
Assigner (CNA)
CVSS severity
CVSS score
CVSS vector
AV:N/AC:M/Au:N/C:C/I:N/A:N
Effective score
7.5 / 10 HIGH source: AI estimate
CWE(s)
Reserved
Published
2021-06-11 00:00 UTC
Last updated
Source
https://www.rapid7.com/db/vulnerabilities/gitlab-gitlab-cve-2021-22175/
Linked Threat
CVE-2021-22175 — GitLab GitLab: GitLab Server-Side Request Forgery (SSRF) Vulnerability

CISA Known Exploited Vulnerabilities CISA KEV

CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.

Vulnerability name
GitLab Server-Side Request Forgery (SSRF) Vulnerability
Vendor / project
GitLab
Product
GitLab
Date added to KEV
2026-02-18
Remediation due
2026-03-11
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Ransomware campaign use
Unknown
CISA notes
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22175.json ; https://nvd.nist.gov/vuln/detail/CVE-2021-22175
CISA listing
www.cisa.gov/known-exploited-vulnerabilities-catalog

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

EPSS score
0.5337 (probability of exploitation in next 30 days)
EPSS percentile
98.85% vs all CVEs — higher = more likely to be exploited, as of 2026-06-28

NVD / KEV / EPSS data refreshed 2026-06-29 04:58 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

AI-forensic CVSS estimate

Used only when a CVE has no official CVSS from its CNA or NVD. An LLM estimates the v3.1 base score from the description; a HIGH/CRITICAL estimate promotes the CVE to a Threat.

Estimated CVSS
CVSS 7.5 / 10 7.5 7.5 / 10 HIGH AI estimate — not authoritative
Estimated at
2026-07-16 20:55 UTC

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2021-9321
Assigner
GitLab
Published
Jun 11, 2021, 3:30:12 PM
Updated
Feb 19, 2026, 4:55:37 AM
EUVD base score (CVSS 3.1)
6.8 / 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
EUVD-reported EPSS
53.3700
Vendors
GitLab
Products
GitLab (13.7, <13.7.7)
GitLab (13.8, <13.8.4)
GitLab (10.5, <13.6.7)
Aliases
GHSA-4gm2-v7j4-74p8

ENISA description: When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

EUVD references (3)

Vendor references (0)

References embedded in the original CVE record by the assigning CNA.

None in the CVE record.

MITRE references (2) cveawg.mitre.org

Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.

Web references (6)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

Indicators (2)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
cwe CWE-918 no local data 2026-05-14 02:58 UTC
cve CVE-2021-22175 no local data 2026-05-14 02:58 UTC

Flagged vendors

    Remediations (16)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:blog.qualys.com

      Key Takeaways RedSun is a critical zero-day vulnerability in Microsoft Defender that allows low-privileged users to gain SYSTEM access No patch is currently available, leaving all Defender-enabled Windows systems potentially exposed Qualys VMDR detects affected assets instantly (QID 92382) TruRisk™ Eliminate enables immediate mitigation , removing exploitability without waiting for a fix ...

      2026-06-04 08:37 UTC
    • web:jumpcloud.com

      Master patch compliance with this technical guide covering vulnerability scanning, deployment processes, key metrics, and remediation best practices.

      2026-06-04 08:37 UTC
    • web:portal.msrc.microsoft.com

      The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

      2026-06-04 08:37 UTC
    • web:support.servicenow.com

      Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...

      2026-06-04 08:37 UTC
    • web:www.bleepingcomputer.com

      CISA has ordered government agencies to secure their systems against a high-severity Oracle WebLogic Server vulnerability that was patched two years ago and is now actively exploited in attacks.

      2026-06-04 08:37 UTC
    • web:www.microsoft.com

      These Knowledge Base articles accompany all security updates and advisories, and include caveats or known issues with security updates. Additionally, support engineers document common concerns from customers in these KB articles. These Knowledge Base articles are published the Security Update Guide with each release on Patch Tuesday.

      2026-06-04 08:37 UTC
    • web:www.oracle.com

      Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.

      2026-06-04 08:37 UTC
    • web:www.oracle.com

      Oracle Critical Patch Update Advisory - April 2025 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical Patch ...

      2026-06-04 08:37 UTC
    • web:www.windowscentral.com

      A faulty BitLocker configuration is forcing some PCs into BitLocker recovery mode after the April 2026 update, but there's a workaround to resolve this issue.

      2026-06-04 08:37 UTC
    • web:zecurit.com

      Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .

      2026-06-04 08:37 UTC
    • web:gbhackers.com

      Microsoft has released its September 2025 Patch Tuesday update, addressing a total of 81 security vulnerabilities across its product portfolio.

      2026-05-14 15:20 UTC
    • web:github.com

      Scripts to install Windows 11 25H2 on unsupported PCs (Fast/Advanced/Reset). - tips2fix/Tips2Fix-Windows11-Installer

      2026-05-14 15:20 UTC
    • web:krebsonsecurity.com

      Microsoft this week pushed security updates to fix more than 60 vulnerabilities in its Windows operating systems and supported software, including at least one zero-day bug that is already being ...

      2026-05-14 15:20 UTC
    • web:cybersecuritynews.com

      Microsoft released its final Patch Tuesday updates of 2025 on December 9, addressing 56 security vulnerabilities across Windows, Office, Exchange Server, and other components.

      2026-05-14 15:20 UTC
    • web:www.rapid7.com

      Microsoft is addressing 176 vulnerabilities this September 2025 Patch Tuesday, which is a lot. This includes a zero-day denial of service vulnerability in SQL Server.

      2026-05-14 15:20 UTC
    • CISA KEV

      Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-03-11 Known ransomware campaign use: Unknown

      2026-05-14 01:13 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2021-22175.json.

    Not stored.