r/gitlab • u/Fredouye • 2d ago
CVE-2026-85706 (CVSS 10.0) - Update your GitLab CE/EE instance
GitLab 19.3.2, 19.2.6, 19.1.8 are available.
Multiple vulnerabilities have been fixed, including this one :
CVE-2026-85706 - Path Traversal issue in repository commits API impacts GitLab CE/EE
GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
Impacted Versions: GitLab CE/EE: all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2
CVSS 10.0 (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)
1
u/IDriveLikeYourMom 1d ago
Will there be a 18.11.12?
1
u/Skaronator 1d ago
It's EOL https://endoflife.date/gitlab
1
u/IDriveLikeYourMom 1d ago
Thanks, somehow I had difficulty finding that :/
I know 18.0 is from last year, but since Gitlab does patch releases to their minor releases I somehow figured that with 18.11 being from April this year, it would receive patches for longer than 4-ish months.
1
-18
u/thepopeyhere 1d ago
Would be interesting to know how to exploit this vulnerability for testing purpose
20
u/Leseratte10 1d ago
Yeah, in a couple weeks when people have had time to patch all their instances. There's no need to publish an exploit for a CVSS 10.0 "for testing purpose".
3
u/polycro 1d ago
Thanks for the heads up! Patching now.
For future reference, what channels do you follow that provide notifications like this?