GitLab vendor intelligence

GitLab Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting GitLab products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse GitLab KEVs Full KEV feed
Total KEVs
7
Known exploited vulnerabilities affecting GitLab products
In CISA KEV
4
Records also listed in the official catalog
Beyond CISA KEV
3
Additional exploited CVEs absent from CISA KEV
Sensor Observed
1
GitLab KEV with sensor-observed exploitation activity

The catalog gap matters for GitLab exposure

Three of the seven exploited GitLab CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 43% of this vendor portfolio.

57%
Covered by CISA
43%
Beyond CISA
1
Product families

Attested GitLab CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2023-2825

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal...

GitLab Confirmed Beyond CISA 03 Aug 2026
CVE-2021-22175

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions...

GitLab Confirmed In CISA 01 Jun 2026
CVE-2021-39935

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before...

GitLab Confirmed In CISA 01 Jun 2026
CVE-2021-4191

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with...

GitLab High Beyond CISA 28 Apr 2025
CVE-2021-22205

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were...

GitLab Confirmed In CISA 03 Nov 2021
CVE-2023-7028

Weak Password Recovery Mechanism for Forgotten Password in GitLab

GitLab Confirmed In CISA 01 May 2024
CVE-2021-22214

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions...

GitLab High Beyond CISA 08 Jun 2021

Showing 7 of 7 GitLab known exploited vulnerabilities.

Recurring weakness patterns

Server-side request forgery (ssrf), limitation, and weak password recovery mechanism for forgotten password account for five mapped occurrences across this GitLab KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.