Critical Vulnerabilities in GitLab Software

GitLab has published information about two critical vulnerabilities - CVE-2026-85706 (with a CVSS score of 10.0) and CVE-2026-87719 (with a CVSS score of 9.9). The CVE-2026-85706 vulnerability involves insufficient path traversal and authentication checks, allowing an unauthenticated attacker to read files from the GitLab server via the repository change approval API. The CVE-2026-87719 vulnerability allows an authenticated user with access to GitLab Duo Chat to send a specially crafted GraphQL subscription request to bypass data serialization protections, access server objects, and retrieve configuration data for advanced search instances, including sensitive access information. Users are advised to update to versions 19.3.2, 19.2.6, or 19.1.8 as soon as possible. More information: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source