The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch their systems against a five-year-old GitLab vulnerability that is actively being exploited in attacks. GitLab patched this server-side request forgery (SSRF) flaw (tracked as CVE-2021-39935) in December 2021, saying it could allow unauthenticated attackers with no privileges to access the CI Lint API, which is used to simulate pipelines and validate CI/CD configurations. "When user registration is limited, external users that aren't developers shouldn't have access to the CI Lint API," the company said at the time. "An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API." On Tuesday, CISA added the flaw to its list of vulnerabilities exploited in the wild and ordered Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three weeks, by February 24, 2026, as mandated by Binding Operational Directive (BOD) 22-01. While BOD 22-01 targets only federal agencies, CISA has urged all organizations, including those in the private sector, to prioritize securing their devices against ongoing CVE-2021-39935 attacks. "These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the feder...
CISA warns of five-year-old GitLab flaw exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Feb 4, 2026
·Updated
Affected Software
6 affected components
GitLab CE>=10.5, <14.3.6
GitLab EE>=10.5, <14.3.6
GitLab CE>=14.4, <14.4.4
GitLab EE>=14.4, <14.4.4
GitLab CE>=14.5, <14.5.2
GitLab EE>=14.5, <14.5.2
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a five-year-old vulnerability in GitLab that is currently being exploited, prompting warnings from CISA.
2
What security implications are discussed in the article?
The article highlights the potential risks of exploitation of the GitLab vulnerability, urging organizations to apply patches immediately.
3
What products or software are affected by the GitLab vulnerability?
The affected products include GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 10.5 to 14.5.2.
4
Who issued the warning regarding the GitLab flaw?
The warning was issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
5
What action is recommended for organizations using the affected GitLab versions?
Organizations are recommended to patch their systems against the vulnerable versions of GitLab to mitigate potential attacks.