Description
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 18 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Wed, 18 Feb 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-02-19T04:55:37.221Z
Reserved: 2021-01-05T00:00:00.000Z
Link: CVE-2021-22175
Updated: 2024-08-03T18:37:18.364Z
Status : Analyzed
Published: 2021-06-11T16:15:09.023
Modified: 2026-02-18T20:07:28.803
Link: CVE-2021-22175
No data.
OpenCVE Enrichment
No data.
Weaknesses