• News/
  • https://www.bleepingcomputer.com/news/security/cisa-warns-of-five-year-old-gitlab-flaw-exploited-in-attacks/

CISA warns of five-year-old GitLab flaw exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Feb 4, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch their systems against a five-year-old GitLab vulnerability that is actively being exploited in attacks. GitLab patched this server-side request forgery (SSRF) flaw (tracked as CVE-2021-39935) in December 2021, saying it could allow unauthenticated attackers with no privileges to access the CI Lint API, which is used to simulate pipelines and validate CI/CD configurations. "When user registration is limited, external users that aren't developers shouldn't have access to the CI Lint API," the company said at the time. "An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API." On Tuesday, CISA added the flaw to its list of vulnerabilities exploited in the wild and ordered Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three weeks, by February 24, 2026, as mandated by Binding Operational Directive (BOD) 22-01. While BOD 22-01 targets only federal agencies, CISA has urged all organizations, including those in the private sector, to prioritize securing their devices against ongoing CVE-2021-39935 attacks. "These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the feder...

Read full article

Affected Software

6 affected components
GitLab CE>=10.5, <14.3.6
GitLab EE>=10.5, <14.3.6
GitLab CE>=14.4, <14.4.4
GitLab EE>=14.4, <14.4.4
GitLab CE>=14.5, <14.5.2
GitLab EE>=14.5, <14.5.2
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a five-year-old vulnerability in GitLab that is currently being exploited, prompting warnings from CISA.

2

What security implications are discussed in the article?

The article highlights the potential risks of exploitation of the GitLab vulnerability, urging organizations to apply patches immediately.

3

What products or software are affected by the GitLab vulnerability?

The affected products include GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 10.5 to 14.5.2.

4

Who issued the warning regarding the GitLab flaw?

The warning was issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

5

What action is recommended for organizations using the affected GitLab versions?

Organizations are recommended to patch their systems against the vulnerable versions of GitLab to mitigate potential attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203