GitLab Server-Side Request Forgery (SSRF) Vulnerability
GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.
GitLabGitLab
Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Evidence reason details
Eligible evidence is present for this bounded claim.
- Revision
evidence-policy-v1.1.0- Cutoff
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
evidence-policy-v1.1.0- Cutoff
- Resolution
- None
Eligible assertions materially conflict and remain visible side by side.
- Revision
casca-direct-cvss-eligibility-v1- Cutoff
- Resolution
- Resolve conflict
The source assertion is retained, but its canonical identity is unresolved.
- Revision
casca-factor-d-obligations-v1- Cutoff
- Resolution
- Resolve identity
- Added
- 2026-02-18
- Due
- 2026-03-11
- Priority interval
- 74.3–83.3
- Coverage
- 85%