CVE Tools

GitLab urges users to patch max severity path traversal flaw

BleepingComputerBy Sergiu Gatlan

PatchGitLab CEGitLab EE

Our summary

GitLab has released urgent security updates for its Community Edition and Enterprise Edition platforms to address a maximum-severity path traversal vulnerability identified as CVE-2026-85706. This flaw, located in the repository commits API, lacks proper path confinement and authentication controls, potentially enabling unauthenticated attackers to read arbitrary files from affected servers under specific conditions.

Simultaneously, the vendor addressed a second critical issue, CVE-2026-87719, involving insecure deserialization in the GraphQL subscription serializer that could expose sensitive credentials to authenticated users with Duo Chat access. Administrators are advised to upgrade self-managed installations to versions 19.3.2, 19.2.6, or 19.1 immediately to mitigate these risks.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store