CISA Alerts on Exploited GitLab SSRF Vulnerability in Community and Enterprise Editions
Article Content
Browse articles
CISA has added a critical server-side request forgery (SSRF) vulnerability in GitLab Community and Enterprise editions, tracked as CVE-2021-39935, to its Known Exploited Vulnerabilities catalog. This vulnerability is currently being exploited by threat actors, posing risks to organizations using affected versions of GitLab. The vulnerability was added to the KEV list on February 3, 2026, indicating active exploitation.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track CVE-2021-39935 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…
SSRF Vulnerability in Sentry MCP Server Exposes Security Risks On July 12, 2026, researcher cccccccti disclosed a Server-Side Request Forgery (SSRF) vulnerability in the raw_sentry_api component of ddfourtwo/sentry-selfhosted-mcp, tracked as CVE-2026-81421. This vulnerability allows attackers to force Axios to call arbitrary endpoints, with a public exploit already available. As…