GitLab Product Security Update Advisory (CVE-2026-85706)

GitLab Product Security Update Advisory (CVE-2026-85706)
  • A security update addressing vulnerabilities in GitLab products has been released.
  • The resolved vulnerability is CVE-2026-85706, an arbitrary file read vulnerability caused through path traversal (an attack that manipulates file paths beyond the permitted directory scope) in the GitLab CE/EE repository commit API.
  • The affected versions are as follows:
    • GitLab CE/EE versions: 18.7 Through 18.1.7.
    • GitLab CE/EE versions: 19.2 Through 19.2.6.
    • GitLab CE/EE versions: 19.3 Or higher, but less than 19.3.2.
  • The patched versions for this vulnerability are as follows:
    • GitLab CE/EE version: 19.1.8.
    • GitLab CE/EE version: 19.2.6.
    • GitLab CE/EE version: 19.3.2.
  • GitLab has advised users to update to the latest version that includes the Vulnerability Patch, following the instructions provided on the reference site.