Wire · regulatory
One HTTP Request, Every File on the Server: GitLab's CVSS 10 Commits-API Flaw Hits ...
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 12 September 2026 · Fusion42 review
A critical CVSS 10 path traversal vulnerability in GitLab's commits API allows unauthenticated attackers to read arbitrary files via a single HTTP POST, with active exploitation starting hours after disclosure. CISA has mandated patching by September 14, 2026, but more than 20,000 self-managed GitLab instances remain vulnerable, posing a severe risk to source code, CI/CD secrets, and supply chain integrity.
This Wire brief sits within Fusion42's coverage of Cybersecurity, Developer Tools and Enterprise Software, and 2 sources have reported it.
◆ ◆ The Wire takeaway
Your GitLab self-managed instance is a ticking time bomb for attackers aiming to steal source code and CI/CD secrets. Patch immediately or risk supply-chain attacks that could poison every downstream pipeline you rely on.
◆ Coverage
2 sources · 12 Sep 2026
◆ Related on Wire
◆ Topics