GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
- ID
- 23608
- Status
- new
- Published
- 12 Sep 2026, 12:30 AM
- Fetched
- 12 Sep 2026, 2:35 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Excerpt
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under
Summary
No summary yet. It will appear after the daemon summarizes this item.