Skip to content
COOEY

FAIL › dossier

GitLab

VENDOR

· dossier confidence 50%

GitLab is a prominent DevOps platform with a history of significant security vulnerabilities, including critical RCE and high-severity SSRF flaws, though it has shown remediation efforts post-discovery.

PROFILE
CategoryDevOps/CI-CD PlatformWhat they doGitLab provides an integrated DevOps platform for software development, including source code management, CI/CD pipelines, and security scanning.
SECURITY POSTURE

GitLab has a mixed security track record with multiple high and critical vulnerabilities, particularly around SSRF, RCE via image uploads, and access control flaws, though it has remediated some issues post-discovery.

Notable failures
  • CVE-2021-22205 critical RCE via image upload
  • CVE-2021-22175 high SSRF enabling internal network access
  • CVE-2021-39935 high SSRF allowing CI Lint API manipulation
Patterns: repeated SSRF vulnerabilities enabling internal network access; critical RCE via improper file validation (ExifTool); access control flaws leading to account takeovers
Reputationneutral (-0.35) · 2 trusted sources Coveragecooey
FAILURE HISTORY · 11
DATEEVENTSEVSUMMARY
2026-02-18 CVE-2021-22175 high GitLab exposed SSRF, enabling internal network requests exploited in the wild
2026-02-18 CVE-2021-22175 high GitLab exposed SSRF, enabling internal network requests exploited in the wild
2026-02-03 CVE-2021-39935 high GitLab SSRF allowed unauthorized external users to manipulate CI Lint API requests
2021-11-03 CVE-2021-22205 critical GitLab's image upload functionality allowed remote code execution due to improper validation of image files by ExifTool, actively exploited in ransomware attacks.
2024-05-01 CVE-2023-7028 high GitLab exploited an access control flaw to send password reset emails to unverified addresses, enabling account takeovers.
2026-08-12 CVE-2026-16627 high CVE-2026-16627: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2
2026-08-12 CVE-2026-16627 high CVE-2026-16627: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2
2026-01-09 CVE-2025-13761 high CVE-2025-13761: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6
2026-01-09 CVE-2025-13761 high CVE-2025-13761: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6
2021-04-23 CVE-2021-22205 critical CVE-2021-22205: An issue has been discovered in GitLab CE/EE affecting all versions starting fro
2021-04-23 CVE-2021-22205 critical CVE-2021-22205: An issue has been discovered in GitLab CE/EE affecting all versions starting fro
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.70
synthesisneutral+0.00
factual reporting
cooey ↗severe-fallout-0.70
negative
"GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files."
cooey ↗neutral+0.00
factual reporting
"An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution."
Open questions: Current patch status for CVE-2021-22205 in older GitLab versions · GitLab's current security testing and vulnerability disclosure process
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-11 03:52:52.613281+00:00