CVE-2022-0136: GitLab

High severity, CVSS 8.1. EPSS: 1% chance of exploitation in the next 30 days.

A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.

Affected products

  • GitLab GitLab: from 10.5.0, up to and including 14.5.4; from 14.6, up to and including 14.6.4; from 14.7.0, up to and including 14.7.1

Published 2022-03-28. Last modified 2026-06-17.