<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — GitLab</title><description>Actively exploited vulnerabilities affecting GitLab products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/gitlab.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2021-22175 — GitLab Server-Side Request Forgery (SSRF) Vulnerability</title><link>https://wildfortech.com/security#CVE-2021-22175</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2021-22175</guid><description>This GitLab vulnerability allows attackers to abuse webhook functionality to make the GitLab server issue requests to internal network resources on their behalf — a classic SSRF attack. When webhooks pointing to internal addresses are permitted, an attacker could potentially reach services behind the firewall that should never be externally accessible, enabling reconnaissance or interaction with internal infrastructure. This is especially dangerous in environments where GitLab sits on a network with access to sensitive internal systems.</description><pubDate>Wed, 18 Feb 2026 00:00:00 GMT</pubDate><category>GitLab</category><category>GitLab</category></item><item><title>CVE-2021-39935 — GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability</title><link>https://wildfortech.com/security#CVE-2021-39935</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2021-39935</guid><description>This vulnerability in GitLab&apos;s Community and Enterprise Editions allows unauthorized external users to abuse the CI Lint API to trigger server-side requests. In practice, an attacker could use GitLab itself as a proxy to reach internal network resources, bypass perimeter controls, or probe services that should not be externally accessible. This is particularly dangerous in environments where GitLab can reach sensitive internal infrastructure, making it a potential pivot point for deeper network compromise.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate><category>GitLab</category><category>Community and Enterprise Editions</category></item></channel></rss>