A single HTTP POST request to the /api/v4/projects/{id}/repository/commits/ endpoint is sufficient to bypass security controls and read arbitrary files from a GitLab server. This path traversal ...
GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.
GitLab patched a maximum-severity vulnerability that could allow an unauthenticated attacker to read arbitrary files from a self-managed server. CISA added the flaw to its Known Exploited ...
GitLab, the hugely popular devops platform, today announced the introduction of secrets detection with version 11.9 of the service. This means that should someone inadvertently include an API key or ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks.
Popular DevSecOps platform GitLab is being actively targeted by hackers attempting to exploit a recently patched, critical path traversal vulnerability. See Also: Cut SIEM Costs by Simplifying Your ...
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706.
In 2026, GitLab Inc. released GitLab 19.4, expanding GitLab Duo’s agentic automation across the platform, adding new open weight models, governance controls, and detailed GitLab Credits usage ...