Critical vulnerability in GitLab puts millions of servers at risk
Security firm SlowMist warns of a critical vulnerability in GitLab CE and EE that allows unauthenticated attackers to read arbitrary files from affected servers. The flaw in the Repository Commits API has been assigned the maximum CVSS score of 10.0 and is registered as CVE-2026-85706.
In brief:
- Critical path traversal vulnerability in GitLab with a CVSS score of 10.0
- GitLab has released security patches for versions 19.1.8, 19.2.6 and 19.3.2
- Users must update immediately and check logs for suspicious activity
Which versions are vulnerable
The vulnerability affects multiple GitLab versions. Versions 18.7 through 19.1.7, versions 19.2 through 19.2.5 and versions 19.3 through 19.3.1 are affected.
GitLab has released security patches. Users of self-managed GitLab installations should immediately upgrade to version 19.1.8, 19.2.6 or 19.3.2, depending on their current version.
What you should do
SlowMist advises all affected users to update immediately. After installing the patch, it is crucial to review the server logs for suspicious access attempts and potentially leaked login credentials.
The nature of the vulnerability means that attackers may have been able to view sensitive files before the patch was installed. It is therefore important to actively search for traces of abuse and to reset passwords and tokens stored on servers.
Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.
Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.