A single HTTP POST to the commits API bypasses all security controls and reads arbitrary files from a GitLab server. CISA gave agencies until September 14 to patch. watchTowr saw exploitation attempts ...
GitLab patched a maximum-severity vulnerability that could allow an unauthenticated attacker to read arbitrary files from a self-managed server. CISA added the flaw to its Known Exploited ...
GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results