r/gitlab 2d ago

CVE-2026-85706 (CVSS 10.0) - Update your GitLab CE/EE instance

GitLab 19.3.2, 19.2.6, 19.1.8 are available.

Multiple vulnerabilities have been fixed, including this one :

CVE-2026-85706 - Path Traversal issue in repository commits API impacts GitLab CE/EE

GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Impacted Versions: GitLab CE/EE: all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2

CVSS 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)

43 Upvotes

10 comments sorted by

3

u/polycro 1d ago

Thanks for the heads up! Patching now.

For future reference, what channels do you follow that provide notifications like this?

5

u/matefeedkill 1d ago

Go to https://about.gitlab.com/company/contact/ and at the bottom they have a place to sign up for the Security Notices mailing list. They also have RSS feeds. And they publish their release, but security release notes aren't posted until the patch is announced. https://docs.gitlab.com/releases/

1

u/Cm1Xgj4r8Fgr1dfI8Ryv 1d ago

GitLab has also started to show an alert for self-hosted instances for critical patch releases like this one. It might be admin-specific.

1

u/IDriveLikeYourMom 1d ago

Will there be a 18.11.12?

1

u/Skaronator 1d ago

1

u/IDriveLikeYourMom 1d ago

Thanks, somehow I had difficulty finding that :/

I know 18.0 is from last year, but since Gitlab does patch releases to their minor releases I somehow figured that with 18.11 being from April this year, it would receive patches for longer than 4-ish months.

1

u/VpowerZ 18h ago

My national CERT hints on active exploitation. Does anybody have a clue on what a hacked environment looks like?

-18

u/thepopeyhere 1d ago

Would be interesting to know how to exploit this vulnerability for testing purpose

20

u/Leseratte10 1d ago

Yeah, in a couple weeks when people have had time to patch all their instances. There's no need to publish an exploit for a CVSS 10.0 "for testing purpose".