CVE-2026-85706 - Path Traversal issue in repository commits API impacts GitLab CE/EE
GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
Impacted Versions: GitLab CE/EE: all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2
CVSS 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)
Thanks s3ntago for reporting this vulnerability through our HackerOne bug bounty program.
CVE-2026-87719 - Insecure Deserialization issue in GraphQL subscription serializer impacts GitLab EE
GitLab has remediated an issue that, under certain conditions, could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.
Impacted Versions: GitLab EE: all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2
CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Thanks kyyblin for reporting this vulnerability through our HackerOne bug bounty program.
GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/?nav=19.3.2
10/10 и 9.9/10 за раз это реально круто, давно такого не видел. Так что реально обновляемся.