FAIL › dossier
GitLab
VENDOR· dossier confidence 50%
GitLab is a prominent DevOps platform with a history of significant security vulnerabilities, including critical RCE and high-severity SSRF flaws, though it has shown remediation efforts post-discovery.
PROFILE
CategoryDevOps/CI-CD PlatformWhat they doGitLab provides an integrated DevOps platform for software development, including source code management, CI/CD pipelines, and security scanning.
SECURITY POSTURE
GitLab has a mixed security track record with multiple high and critical vulnerabilities, particularly around SSRF, RCE via image uploads, and access control flaws, though it has remediated some issues post-discovery.
Notable failures
- CVE-2021-22205 critical RCE via image upload
- CVE-2021-22175 high SSRF enabling internal network access
- CVE-2021-39935 high SSRF allowing CI Lint API manipulation
Patterns: repeated SSRF vulnerabilities enabling internal network access; critical RCE via improper file validation (ExifTool); access control flaws leading to account takeovers
FAILURE HISTORY · 11
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-02-18 | CVE-2021-22175 | high | GitLab exposed SSRF, enabling internal network requests exploited in the wild |
| 2026-02-18 | CVE-2021-22175 | high | GitLab exposed SSRF, enabling internal network requests exploited in the wild |
| 2026-02-03 | CVE-2021-39935 | high | GitLab SSRF allowed unauthorized external users to manipulate CI Lint API requests |
| 2021-11-03 | CVE-2021-22205 | critical | GitLab's image upload functionality allowed remote code execution due to improper validation of image files by ExifTool, actively exploited in ransomware attacks. |
| 2024-05-01 | CVE-2023-7028 | high | GitLab exploited an access control flaw to send password reset emails to unverified addresses, enabling account takeovers. |
| 2026-08-12 | CVE-2026-16627 | high | CVE-2026-16627: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 |
| 2026-08-12 | CVE-2026-16627 | high | CVE-2026-16627: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 |
| 2026-01-09 | CVE-2025-13761 | high | CVE-2025-13761: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 |
| 2026-01-09 | CVE-2025-13761 | high | CVE-2025-13761: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 |
| 2021-04-23 | CVE-2021-22205 | critical | CVE-2021-22205: An issue has been discovered in GitLab CE/EE affecting all versions starting fro |
| 2021-04-23 | CVE-2021-22205 | critical | CVE-2021-22205: An issue has been discovered in GitLab CE/EE affecting all versions starting fro |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.70
…
synthesisneutral+0.00
factual reporting
negative
"GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files."
factual reporting
"An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution."
Open questions: Current patch status for CVE-2021-22205 in older GitLab versions · GitLab's current security testing and vulnerability disclosure process
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-11 03:52:52.613281+00:00