GitLab urges users to patch max severity path traversal flaw
Key Points:
- GitLab has released urgent patches for two critical vulnerabilities, CVE-2026-85706, a path traversal flaw allowing unauthenticated attackers to read arbitrary data, and CVE-2026-87719, an insecure deserialization issue affecting authenticated users with Duo Chat access.
- The path traversal vulnerability CVE-2026-85706 was discovered via GitLab's bug bounty program and is already being actively probed by attackers searching for unpatched Internet-exposed GitLab servers.
- GitLab patched these flaws in versions 19.3.2, 19.2.6, and 19.1 for both Community and Enterprise Editions and strongly urged all self-managed installations to update immediately; GitLab.com and Dedicated customers are already protected.
- These recent vulnerabilities follow a history of critical security issues in GitLab, including previous path traversal flaws and two-factor authentication bypasses, with multiple vulnerabilities flagged by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as exploited in the wild.
- GitLab’s DevSecOps platform serves over 30 million users and more than half of Fortune 100 companies, highlighting the importance of prompt patching to protect sensitive data and maintain supply chain security.