← Back

Wire · regulatory

One HTTP Request, Every File on the Server: GitLab's CVSS 10 Commits-API Flaw Hits ...

Published

12 September 2026

Topic

regulatory

Sectors

CybersecurityDeveloper ToolsEnterprise Software

Source

Read at forkast.news

Verified

Fusion42 · 12 September 2026 · Fusion42 review

A critical CVSS 10 path traversal vulnerability in GitLab's commits API allows unauthenticated attackers to read arbitrary files via a single HTTP POST, with active exploitation starting hours after disclosure. CISA has mandated patching by September 14, 2026, but more than 20,000 self-managed GitLab instances remain vulnerable, posing a severe risk to source code, CI/CD secrets, and supply chain integrity.

This Wire brief sits within Fusion42's coverage of Cybersecurity, Developer Tools and Enterprise Software, and 2 sources have reported it.

◆ The Wire takeaway

Your GitLab self-managed instance is a ticking time bomb for attackers aiming to steal source code and CI/CD secrets. Patch immediately or risk supply-chain attacks that could poison every downstream pipeline you rely on.

Coverage

2 sources · 12 Sep 2026

Related on Wire

Topics

CybersecurityDeveloper ToolsEnterprise Softwaregitlabsecuritypath-traversalcisapatch-mandate