"These versions contain important bug and security fixes, and we strongly recommend that all self‑managed GitLab installations be upgraded to one of these versions immediately," GitLab warned on Thursday.
CVE-2026-85706: a maximum-severity path traversal that can expose files
GitLab on Thursday urged users to patch immediately against a maximum‑severity path traversal vulnerability tracked as CVE-2026-85706. The flaw was reported to GitLab's HackerOne bug bounty program by a researcher using the handle "s3ntago." According to GitLab, the error "stems from improper path confinement and missing authentication enforcement in the repository commits API." Under those conditions, unauthenticated attackers can exploit CVE-2026-85706 to read arbitrary files from vulnerable servers "under certain conditions."
CVE-2026-87719: insecure deserialization and credential exposure in EE
On the same day GitLab also patched a second critical vulnerability, CVE-2026-87719, which the company says stems from an insecure deserialization weakness in the GraphQL subscription serializer. GitLab stated CVE-2026-87719 affects GitLab Enterprise Edition (EE) and allows authenticated users with Duo Chat access to steal sensitive credentials and Advanced Search instance configurations.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildPatched releases, who must act, and GitLab's deployment status
GitLab fixed both issues in Community Edition (CE) and Enterprise Edition (EE) releases 19.3.2, 19.2.6, and 19.1 on Thursday and again urged immediate upgrades to those versions for self‑managed installations. GitLab also reported that GitLab.com is already running the patched version and that GitLab Dedicated customers do not need to take action.
The company’s advisory makes two operational distinctions clear: self‑managed instances must upgrade to one of the patched versions immediately, while GitLab’s hosted service is already updated and Dedicated customers are not required to intervene.
What this means for technologists, CISA and the FBI, and large enterprises (Nvidia, Airbus, T‑Mobile, Lockheed Martin, Goldman Sachs, UBS)
- Technologists and security teams: teams running self‑managed GitLab must prioritize updating to 19.3.2, 19.2.6, or 19.1 and verify that repository commits API endpoints are not accessible without appropriate authentication and path confinement controls.
- CISA and the FBI: the advisory sits against a backdrop in which U.S. agencies have previously urged vendors to eliminate path traversal flaws, and in which CISA has flagged GitLab vulnerabilities as exploited. The agencies' prior calls to action about path traversal vulnerabilities amplify the urgency of the current patches.
- Large enterprises named by GitLab: organizations that use the platform — GitLab reports more than 30 million registered users and usage by over 50% of Fortune 100 companies, including Nvidia, Airbus, T‑Mobile, Lockheed Martin, Goldman Sachs, and UBS — should confirm whether their installations are self‑managed or hosted and ensure upgrades or compensating controls are in place.
Context: recurring path traversal issues and GitLab's recent security history
Path traversal is not new to GitLab. In May 2023 the company addressed another maximum‑severity path traversal flaw (CVE-2023-2825) that exposed sensitive data including proprietary software code, user credentials, tokens, and files on unpatched servers. The source notes that one year later CISA and the FBI urged software companies to remove path traversal vulnerabilities from products before shipping, saying such flaws "have been called 'unforgivable' since at least 2007."
Additional recent fixes cited by GitLab include a January patch for a high‑severity two‑factor authentication bypass that enabled attackers who knew a target's account ID to circumvent two‑factor authentication. Since November 2021, CISA has flagged four GitLab vulnerabilities as exploited in attacks, including two (CVE-2021-22175 and CVE-2021-39935) "in February this year."
GitLab’s dual patches this week close two distinct technical paths to compromise: an unauthenticated path traversal that can expose arbitrary files via the repository commits API, and an authenticated insecure deserialization issue that can disclose credentials and Advanced Search configuration data in EE. For organizations that manage their own GitLab instances, the record is straightforward — upgrade to one of the patched releases immediately; for those on GitLab.com, GitLab reports the update is already in place.
Original story: https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/




