GitLab CVSS 10 File-Read Flaw Faces In-the-Wild Probes
GitLab issued patches for a critical CVSS 10.0 path traversal flaw in its repository commits API that allows unauthenticated file reads and is being actively probed in the wild.
Tag
2 results in the archive.
GitLab issued patches for a critical CVSS 10.0 path traversal flaw in its repository commits API that allows unauthenticated file reads and is being actively probed in the wild.
A critical code injection vulnerability in GitLab, CVE-2026-19478, is actively exploited shortly after disclosure, enabling unauthenticated attackers to modify or delete certain publicly accessible projects.