GitLab Patches Critical File-Read Vulnerability Amidst Active Exploitation
GitLab has released patches for a maximum-severity security vulnerability, CVE-2026-85706, a path traversal issue in its repository commits API. This flaw could allow unauthenticated users to read arbitrary files from the GitLab server. Probes exploiting this vulnerability have been observed in the wild since September 11, 2026, hours after public disclosure, underscoring the urgency of applying the available patches.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai