GitLab issues urgent patch for critical path-traversal flaw CVE-2026-85706

TL;DR Summary
GitLab urges self-hosted installations to patch CVE-2026-85706, a max-severity path traversal flaw in the repository-commits API that could allow unauthenticated access to arbitrary data; patches are available in GitLab CE/EE 19.3.2, 19.2.6, and 19.1, with GitLab.com already on patched code. WatchTowr reports in-the-wild probing for exploitation, and a related issue—CVE-2026-87719 (insecure deserialization in GraphQL subscriptions)—is also fixed in these versions. Admins should upgrade immediately to protect credentials and configs; GitLab serves millions of users, including Fortune 100 companies.
- GitLab urges users to patch max severity path traversal flaw BleepingComputer
- GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure thehackernews.com
- Rapid Reaction: GitLab Path Traversal Vulnerability (CVE-2026-85706) watchtowr.com
- One HTTP Request, Every File on the Server: GitLab’s CVSS 10 Commits-API Flaw Hits Active Exploitation Within Hours forkast.news
- GitLab’s critical flaw is already drawing internet-wide probes CyberScoop
Reading Insights
Total Reads
1
Unique Readers
6
Time Saved
3 min
vs 4 min read
Condensed
90%
744 → 78 words
Want the full story? Read the original article
Read on BleepingComputer