A 10/10 GitLab flaw was added to CISA's KEV, giving government agencies just three days to patch.
The vulnerability impacts self-managed CE and EE instances and provides an unauthenticated path to arbitrary file reads. It’s ...
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and ...
GitLab patched a maximum-severity vulnerability that could allow an unauthenticated attacker to read arbitrary files from a self-managed server. CISA added the flaw to its Known Exploited ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity ...
Attackers are actively targeting a recently patched vulnerability in the popular DevSecOps platform GitLab that they can ...
CISA says attackers are exploiting a maximum-severity GitLab flaw that lets unauthenticated miscreants read arbitrary files ...
The vulnerability could let unauthenticated users access sensitive files from software-development environments.
GitLab users are being urged to patch a maximum severity vulnerability in the platform after reports of “in-the-wild” ...
A single HTTP POST to the commits API bypasses all security controls and reads arbitrary files from a GitLab server. CISA ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results