A 10/10 GitLab flaw was added to CISA's KEV, giving government agencies just three days to patch.
Attackers are actively targeting a recently patched vulnerability in the popular DevSecOps platform GitLab that they can ...
CISA says attackers are exploiting a maximum-severity GitLab flaw that lets unauthenticated miscreants read arbitrary files ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity ...
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and ...
A single HTTP POST request to the /api/v4/projects/{id}/repository/commits/ endpoint is sufficient to bypass security controls and read arbitrary files from a GitLab server. This path traversal ...
GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.
The vulnerability impacts self-managed CE and EE instances and provides an unauthenticated path to arbitrary file reads. It’s ...
GitLab에서 인증되지 않은 공격자가 서버 내 임의 파일을 읽을 수 있는 경로 탐색 취약점이 발견됐다. 해당 취약점의 CVSS 점수는 10.0이다.PANews는 15일 慢雾가 GitLab CE·EE의 CVE-2026-85706을 모니터링한 결과 이 같은 ...
GitLab users are being urged to patch a maximum severity vulnerability in the platform after reports of “in-the-wild” ...