GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
ID: c7b82f16-e528-5df4-bd01-0216f5154758
STIX ID: report--c7b82f16-e528-5df4-bd01-0216f5154758
Feed Name: The Hacker News
GitLab released emergency patches for multiple critical flaws, including CVE-2026-85706 (path traversal, CVSS 10.0) that can allow unauthenticated arbitrary file reads and has been observed in-the-wild since hours after disclosure, and CVE-2026-87719 (insecure deserialization, CVSS 9.9) affecting self-managed instances; organizations are urged to patch immediately or block public access and to review logs for HTTP POSTs to '/api/v4/projects/{id}/repository/commits/' containing 'file.Path' to detect exploitation attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
