GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.
A single HTTP POST request to the /api/v4/projects/{id}/repository/commits/ endpoint is sufficient to bypass security controls and read arbitrary files from a GitLab server. This path traversal ...
GitLab patched a maximum-severity vulnerability that could allow an unauthenticated attacker to read arbitrary files from a self-managed server. CISA added the flaw to its Known Exploited ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks.
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706.
Will GitLab 19.4’s Expanded AI Agent Controls and Cost Transparency Change GitLab's (GTLB) Narrative
In 2026, GitLab Inc. released GitLab 19.4, expanding GitLab Duo’s agentic automation across the platform, adding new open weight models, governance controls, and detailed GitLab Credits usage ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results