Maximum-severity GitLab flaw risks CI/CD trust
🚨 GitLab disclosed CVE-2026-85706, a maximum-severity path traversal flaw in its repository commits API that can allow unauthenticated attackers to read arbitrary files with a single HTTP request. The bug affected Community and Enterprise editions and has been patched; GitLab urged self-hosted, public-facing instances to patch immediately or remove access. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, and threat intel already reports in-the-wild probes. Experts warn this poses broad risk because GitLab often links to build, deployment, and secret-bearing files.