important · Edge — GitLab
Attackers are exploiting GitLab's unauthenticated commit endpoint to read arbitrary server files.
Affects
GitLab Community Edition and Enterprise Edition, self-managed source-code and CI/CD servers.
A crafted commit request reaches File.read without authentication, and malformed percent encoding reflects the selected file through error handling.
Detail and 4 sources
The path has a runnable public reproducer and can disclose every file readable by the GitLab service process.
GitLab has published fixed versions for affected branches.
Sources
ResearchKritieke kwetsbaarheid in GitLab wordt actief misbruikt: update nu | NCSCResearchCVE-2026-85706: GitLab CE/EE unauthenticated path traversal in Repository Commits API...ResearchGitLabのCVSS 10.0欠陥CVE-2026-85706、実証コードが公開され能動的な悪用を確認 — オランダNCSCが更新を警告 | NEXSIGHT CYBER WIRECode / PoCGitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8 | GitLab Docs