GitLab urges immediate patch for critical path flaw
🚨 GitLab has released urgent updates to address a maximum-severity path traversal vulnerability (CVE-2026-85706) discovered in the repository commits API and reported via HackerOne. The flaw allows unauthenticated attackers, under certain conditions, to read arbitrary files from vulnerable servers, potentially exposing credentials and secrets. GitLab patched this and a separate critical insecure deserialization bug (CVE-2026-87719) and strongly urges self-managed instances to upgrade to the fixed CE/EE releases immediately.
