SlowMist|Sep 15, 2026 03:14
🚨 SlowMist TI Alert: CVE-2026-85706 🚨
🔴 A critical path traversal vulnerability in @gitlab CE/EE (CVSS 10.0) could allow unauthenticated attackers to read arbitrary files from affected GitLab servers via the Repository Commits API.
🛠️ GitLab has released security patches to address this vulnerability.
⚠️ Affected:
affected from 18.7 before 19.1.8
affected from 19.2 before 19.2.6
affected from 19.3 before 19.3.2
🚨 Self-managed GitLab users should upgrade to 19.1.8, 19.2.6, or 19.3.2 immediately, and review logs and potentially exposed credentials after patching.
🔐 Stay alert and keep your infrastructure up to date.
🔗 https://www.cve.org/CVERecord?id=CVE-2026-85706
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink