KOSUNI CRYPTO
Korea's Crypto Pulse, in English
$BTC $ETH $XRP $SOL $DOGE
News
Neutral

GitLab Vulnerability with CVSS 10.0 Requires Immediate Patch

Published September 20, 2026 11:13 AM · 1 views
GitLab Vulnerability with CVSS 10.0 Requires Immediate Patch

A critical security flaw in GitLab has been discovered that allows unauthenticated attackers to read arbitrary files within the server. The vulnerability, with a CVSS score of 10.0, was reported by PANews on May 15, citing Moxie's monitoring of CVE-2026-85706 for GitLab CE and EE. Attackers could exploit the Repository Commits API to access files on affected GitLab servers. GitLab has patched the issue in versions 19.1.8, 19.2.6, and 19.3.2. Affected versions include those below 19.1.8 from 18.7 onward, below 19.2.6 for version 19.2, and below 19.3.2 for version 19.3. Self-hosted users are advised to upgrade immediately and check logs and exposed credentials.

Korean Source

This article is an English localization of a Korean-language crypto news report. Original headline: CVSS 10.0 GitLab 취약점…자체 호스팅 즉시 패치