GitLab’s non-expiring incoming email token can let a holder commit code with a user’s permissions and trigger CI/CD jobs.
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that ...
The version control platform GitLab for software projects is vulnerable through several security flaws. In the worst case, ...
GitLab users are being urged to patch a maximum severity vulnerability in the platform after reports of “in-the-wild” ...
Explore the latest news, real-world incidents, expert analysis, and trends in Gitlab — only on The Hacker News, the leading ...
The most serious flaw, CVE-2026-85706, carries a CVSS score of 10.0 and affects both Community Edition and Enterprise Edition. GitLab said improper path confinement and missing authentication ...
Threat actors started exploiting CVE-2026-85706, a critical-severity path traversal in GitLab, one day after public ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity ...
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and ...
GitLab has released security updates to address multiple vulnerabilities in the company's DevSecOps platform, including ones enabling attackers to take over accounts and inject malicious jobs in ...
A 10/10 GitLab flaw was added to CISA's KEV, giving government agencies just three days to patch.
A single HTTP POST to the commits API bypasses all security controls and reads arbitrary files from a GitLab server. CISA ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results