Perfect-10 GitLab bug under attack days after patch lands
- ID
- 24234
- Status
- summarized
- Published
- 14 Sep 2026, 10:30 PM
- Fetched
- 14 Sep 2026, 11:24 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/14/perfect-10-gitlab-bug-under-attack-days-after-patch-lands/5296176
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 8.5
- Created
- 14 Sep 2026, 11:26 PM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
A CVSS 10.0 path traversal flaw (CVE-2026-85706) in GitLab's repository commits API allows unauthenticated attackers to read arbitrary files—including secrets and credentials—via a single HTTP POST request. CISA added it to its Known Exploited Vulnerabilities catalog after watchTowr observed active probing of internet-facing self-managed instances. Patches shipped September 10 in versions 19.3.2, 19.2.6, and 19.1.8; GitLab.com and GitLab Dedicated are already patched.
Why it matters
If your team runs a self-managed GitLab instance exposed to the internet on any version from 18.7 through the affected branches, patch to 19.1.8/19.2.6/19.3.2 immediately or pull it behind a VPN—exploitation is trivial and exposes source code, config files, and stored credentials. Check logs for POST requests to /api/v4/projects/{id}/repository/commits/ with file.path parameters to detect prior probing.
Discussion angle
How many Malaysian dev teams still run internet-facing self-managed GitLab, and is the convenience of public access worth the risk when a single unauthenticated HTTP request can dump your secrets?