← Browse

CVE-2021-22175

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
53.4%
98.9th percentile
CISA KEV
Listed
Added 2026-02-18 · patch by 2026-03-11
Weakness / dates
Published — · modified —

Timeline

Description

GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.

Official: NVD · CVE.org