Critical GitLab Flaw Under Active Attack: Patch Now
GitLab released emergency patches on Thursday for two high-severity vulnerabilities in its software development platform, one of which received the maximum possible severity score of 10.0. Security firm WatchTowr Labs says it has already observed attackers probing the internet for the flaw, warning that widespread exploitation could follow quickly.
The most serious issue, CVE-2026-85706, affects the interface that handles repository commits. It allows an attacker with no account or credentials to read any file on a vulnerable server due to improper file path handling and missing authentication checks. It affects GitLab versions from 18.7 through 19.1.8, as well as early 19.2 and 19.3 releases. A second flaw, CVE-2026-87719, affects GitLab Enterprise Edition and could let a logged-in user with Duo Chat access trick the server into exposing internal settings and passwords through its Advanced Search feature.
GitLab has urged all self-managed users to upgrade immediately, noting its own hosted service is already patched and that Dedicated customers are unaffected. WatchTowr Labs said organisations running self-hosted GitLab servers exposed to the internet face the greatest risk and recommended checking logs for suspicious POST requests to repository commit endpoints containing a file.path parameter.