GitLab will give unauthenticated users and users of its free tier a taste of the new restrictions during two “preview” windows between 3pm and 7pm UTC on October 7 and October 14. The changes will ...
A 10/10 GitLab flaw was added to CISA's KEV, giving government agencies just three days to patch.
A single HTTP POST request to the /api/v4/projects/{id}/repository/commits/ endpoint is sufficient to bypass security controls and read arbitrary files from a GitLab server. This path traversal ...
CISA says attackers are exploiting a maximum-severity GitLab flaw that lets unauthenticated miscreants read arbitrary files ...
GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.
Attackers are actively targeting a recently patched vulnerability in the popular DevSecOps platform GitLab that they can ...
The vulnerability impacts self-managed CE and EE instances and provides an unauthenticated path to arbitrary file reads. It’s ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity ...
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and ...