One HTTP Request, Every File on the Server: GitLab’s CVSS 10 Commits-API Flaw Hits Active Exploitation Within Hours
GitLab patched a critical path traversal vulnerability (CVE-2026-85706, CVSS 10.0) that allows unauthorized file access. Exploits began hours after disclosure. Affected versions include CE/EE 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. The flaw impacts self-managed instances, with 20,000+ estimated at risk. GitLab.com is patched. The issue highlights structural concerns in GitLab's handling of untrusted file paths.
How this was made

The 30-second read
Why it matters
The disclosed vulnerability could lead to data exfiltration, credential theft, and downstream supply‑chain attacks, prompting urgent remediation efforts.
Market read
First report of a critical, actively exploited GitLab vulnerability; likely to trigger short‑term price decline and heightened security spending.
What to watch
Potential increased demand for managed GitLab.com services as customers migrate away from self‑hosted instances.
Background
GitLab is a leading provider of source‑code management and CI/CD tools, with a large base of self‑managed installations.
Market effects
Raises security risk concerns for CI/CD and DevOps tooling providers, potentially affecting peers like Atlassian and Azure DevOps.
Global impact on enterprises using self‑hosted GitLab instances, especially in North America and Europe.
Highlights supply‑chain security vulnerabilities in software development platforms worldwide.
Counterpoint
If GitLab quickly rolls out patches and offers compensation, the stock may recover faster than typical security breach reactions.
Key entities
- companyGitLab
Provider of DevOps platform; subject of the vulnerability disclosure.
- vulnerabilityCVE-2026-85706
Critical path‑traversal flaw in the Commits API.
- regulatorCISA
Added the flaw to its Known Exploited Vulnerabilities catalog.




