AI Weekly Malaysia

Back to items Summaries

Perfect-10 GitLab bug under attack days after patch lands

ID
24234
Status
summarized
Published
14 Sep 2026, 10:30 PM
Fetched
14 Sep 2026, 11:24 PM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/security/2026/09/14/perfect-10-gitlab-bug-under-attack-days-after-patch-lands/5296176
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
8.5
Created
14 Sep 2026, 11:26 PM
Tags
Audience
developersvibe_coderssaas_founders

What happened

A CVSS 10.0 path traversal flaw (CVE-2026-85706) in GitLab's repository commits API allows unauthenticated attackers to read arbitrary files—including secrets and credentials—via a single HTTP POST request. CISA added it to its Known Exploited Vulnerabilities catalog after watchTowr observed active probing of internet-facing self-managed instances. Patches shipped September 10 in versions 19.3.2, 19.2.6, and 19.1.8; GitLab.com and GitLab Dedicated are already patched.

Why it matters

If your team runs a self-managed GitLab instance exposed to the internet on any version from 18.7 through the affected branches, patch to 19.1.8/19.2.6/19.3.2 immediately or pull it behind a VPN—exploitation is trivial and exposes source code, config files, and stored credentials. Check logs for POST requests to /api/v4/projects/{id}/repository/commits/ with file.path parameters to detect prior probing.

Discussion angle

How many Malaysian dev teams still run internet-facing self-managed GitLab, and is the convenience of public access worth the risk when a single unauthenticated HTTP request can dump your secrets?

Top