The US Cybersecurity and Infrastructure Security Agency (CISA) has added a GitLab vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that it is being actively exploited.
GitLab updated its Community Edition (CE) and Enterprise Edition (EE) versions to 19.3.2, 19.2.6, and 19.1. The updates address several vulnerabilities, including two with critical severity.
One is a path traversal flaw in the repository commits API. Tracked as CVE-2026-85706, it has a severity score of 10/10. The issue involves missing authentication enforcement and improper path confinement, allowing unauthenticated attackers to read sensitive information such as login credentials or secrets.
GitLab’s advisory did not say the flaws were being exploited. However, cybersecurity company watchTowr reported a day later that it had observed in-the-wild probes for CVE-2026-85706, which can let attackers read arbitrary files in a single HTTP request. The second critical issue affects the GraphQL subscription serializer and involves Insecure Deserialization.
CISA’s KEV listing gives government users a three-day window to apply the patch. GitLab describes itself as an intelligent orchestration platform for DevSecOps professionals. An SEC filing says it has more than 50 million registered users, including roughly 50% of Fortune 100 companies.
Comments
0No comments yet. Be the first to comment.