Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 12 Sep 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API. | |
| Title | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-09-12T03:55:28.239Z
Reserved: 2026-09-04T14:34:20.856Z
Link: CVE-2026-85706
No data.
Status : Received
Published: 2026-09-12T03:16:30.473
Modified: 2026-09-12T03:16:30.473
Link: CVE-2026-85706
No data.
OpenCVE Enrichment
No data.
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')