GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.
A single HTTP POST request to the /api/v4/projects/{id}/repository/commits/ endpoint is sufficient to bypass security controls and read arbitrary files from a GitLab server. This path traversal ...
GitLab patched a maximum-severity vulnerability that could allow an unauthenticated attacker to read arbitrary files from a self-managed server. CISA added the flaw to its Known Exploited ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks.
Popular DevSecOps platform GitLab is being actively targeted by hackers attempting to exploit a recently patched, critical path traversal vulnerability. See Also: The Anatomy of a Modern Cyberattack ...
In 2026, GitLab Inc. released GitLab 19.4, expanding GitLab Duo’s agentic automation across the platform, adding new open weight models, governance controls, and detailed GitLab Credits usage ...