proomt

Search

Search posts, papers, and topics

All posts

InfoQSergio De Simone2 min readintermediate

GitLab Vulnerability Under Active Exploitation Enables Unauthenticated Data Exfiltration

Summary

CVE-2026-85706 is a critical path-traversal vulnerability in self-managed GitLab CE/EE, allowing unauthenticated attackers to read arbitrary files. It affects versions 18.7-19.3.1 and is under active exploitation, requiring only one public project on the instance.

  • CVE-2026-85706 is a critical (CVSS 10.0) path-traversal flaw in GitLab CE/EE, allowing unauthenticated arbitrary file reads.
  • It affects GitLab CE/EE versions 18.7 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1.
  • Exploitation requires only one public project on the GitLab instance and targets the repository commits API.
  • Beyond patching, rotate all deploy tokens, CI variables, and SSH keys, then check for compromised packages/images.

GitLab administrators and security teams must immediately patch affected instances and perform post-exploitation checks to prevent further system compromise due to active exploitation.

7/10

Related reading

  1. Postmortem of database outage of January 31

    GitLab.com suffered a major outage and data loss when an engineer accidentally wiped the primary PostgreSQL database during a replication resync attempt. Multiple backup and recovery procedures failed, including `pg_dump` due to a version mismatch and silent cronjob failures, leading to significant data loss.

    Hall of Famegitlab.com17 minpostmortem
  2. Best GitLab Alternatives for Enterprise Teams (2026)

    The article is a vendor‑authored marketing piece that lists criteria for picking a GitLab alternative and then promotes CloudBees Unify as a cross‑tool governance layer, with brief mentions of other tools (GitHub, Jenkins, Azure DevOps, Harness, CircleCI). It contains a few quoted survey percentages but no technical deep‑dive, code, architecture diagrams, or independent evaluation.

    Codeshipcloudbees.com10 min
  3. Rate limits on GitLab.com are changing

    GitLab.com will tie API rate limits to subscription tiers: free users (and unauthenticated IPs) get 60 req/hr, while Premium/Ultimate get higher per‑user and per‑group caps starting Oct 19 2026 (free) and Jan 2027 (paid). Authenticated requests use the plan’s limits; hitting a limit returns 429 with Retry‑After. Preview “brownout” windows on Oct 7 and 14 let you test the new caps. If you need mor…

    Hacker News front pagegitlab.com4 minHN174127