CVE-2021-39935

MEDIUM KEV

GitLab 10.5-14.3.5, 14.4-14.4.3, 14.5-14.5.1 - Unauthenticated Server-Side Request Forgery via CI Lint API

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-39935 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added February 3, 2026.

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

References (4)

Core 4
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://gitlab.com/gitlab-org/gitlab/-/issues/346187
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1236965

Scores

CVSS v3 6.8
EPSS 0.6453
EPSS Percentile 98.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact partial

Details

CISA KEV 2026-02-03
VulnCheck KEV 2025-03-11
ENISA EUVD EUVD-2021-26291
CWE
CWE-918
Status published
Products (1)
gitlab/gitlab 10.5.0 - 14.3.6 (2 CPE variants)
Published Dec 13, 2021
KEV Added Feb 03, 2026
Tracked Since Feb 18, 2026