🔴 Critical: GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
-
GitLab has shipped patches for multiple security issues, including a maximum-severity flaw that attackers began probing in the wild within hours of public disclosure.
The most serious issue is CVE-2026-85706, which carries a CVSS score of 10.0. It is a path traversal vulnerability in the repository commits API that could let an unauthenticated user read arbitrary files from the GitLab server.
Details on affected versions and official remediation guidance were not included in the source report, so administrators should consult GitLab's own advisory and apply the available patches as soon as possible. Given the maximum severity rating and evidence of active probing, treating this as an urgent patch is advisable.
Source: The Hacker News
Has anyone seen probe attempts against their GitLab instance yet, and how quickly are you planning to roll out the fix?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login