ALEXKRI.NET
Resume Contact
← Back

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

If you self-host GitLab, this is today’s job. CVE-2026-85706 is a CVSS 10 path traversal in the repository commits API that lets an unauthenticated attacker read arbitrary files, including logs and configs holding credentials, as long as the instance has one public project. Probes started at 06:00 UTC on disclosure day and CISA added it to KEV within hours. Fixed in 19.3.2, 19.2.6 and 19.1.8.

Read the source ↗