logo

CISA warns of five-year-old GitLab flaw exploited in attacks

ID: 12bb26dd-8e66-5e38-a4b7-5f1db2f8dd72

STIX ID: report--12bb26dd-8e66-5e38-a4b7-5f1db2f8dd72

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA added CVE-2021-39935, a five-year-old GitLab SSRF flaw patched in December 2021, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch systems within three weeks due to active exploitation; the report emphasizes widespread exposure (Shodan >49,000 GitLab instances, GitLab used by millions and many Fortune 100 companies) and urges organizations to apply vendor mitigations or discontinue affected products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.