Vendor

GitLab

As of , 5 GitLab vulnerabilities are on CISA's list of exploited vulnerabilities, 1 of them used in ransomware campaigns; 3 were added in 2026. Patch first: CVE-2026-85706.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-85706Path TraversalGitLab Community Edition and Enterprise EditionPatch nowForensic triage required by CISA; Metasploit module0.93
2CVE-2023-7028Community and Enterprise Editions Improper Access ControlGitLab GitLab CE/EEPatch this weekMetasploit module; EPSS 0.950.95
3CVE-2021-22205Remote Code ExecutionGitLab Community and Enterprise EditionsPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
4CVE-2021-22175Server-Side Request Forgery (SSRF)GitLab GitLabPatch this weekEPSS 0.530.53
5CVE-2021-39935Server-Side Request Forgery (SSRF)GitLab Community and Enterprise EditionsPatch soon0.36

Products

  • Community and Enterprise Editions2 entries
  • Community Edition and Enterprise Edition1 entry
  • GitLab1 entry
  • GitLab CE/EE1 entry

Added each year

1232021: 1120212022: nonenone20222023: nonenone20232024: 1120242025: nonenone20252026: 332026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20211
2022none
2023none
20241
2025none
20263

Used in ransomware

Changes CISA made to these entries

  1. CVE-2021-22205 GitLab Community and Enterprise EditionsRansomware use: Unknown to Known.

Every change we recorded