<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/gitlab-s-critical-patch-closes-a-path-traversal-flaw-attackers-are-already-probing-tmn6i0kaw" -->

---
title: GitLab’s Critical Patch Closes a Path Traversal Flaw...
description: GitLab shipped a critical patch (versions 19.3.2, 19.2.6, 19.1.8) on September 10 fixing 18 security vulnerabilities, including CVE-2026-85706, a CVSS 10.0...
canonical: https://daily.dev/posts/gitlab-s-critical-patch-closes-a-path-traversal-flaw-attackers-are-already-probing-tmn6i0kaw
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: GitLab’s Critical Patch Closes a Path Traversal Flaw Attackers Are Already Probing | daily.dev
og:description: GitLab shipped a critical patch (versions 19.3.2, 19.2.6, 19.1.8) on September 10 fixing 18 security vulnerabilities, including CVE-2026-85706, a CVSS 10.0...
og:url: https://daily.dev/posts/gitlab-s-critical-patch-closes-a-path-traversal-flaw-attackers-are-already-probing-tmn6i0kaw
og:image: https://api.daily.dev/og/posts/TMN6I0KaW.png
og:image:alt: GitLab’s Critical Patch Closes a Path Traversal Flaw Attackers Are Already Probing
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# GitLab’s Critical Patch Closes a Path Traversal Flaw Attackers Are Already Probing

**[DevOps.com](https://daily.dev/sources/devops)** · 6 min read · 0 upvotes · 0 comments

## Summary

GitLab shipped a critical patch (versions 19.3.2, 19.2.6, 19.1.8) on September 10 fixing 18 security vulnerabilities, including CVE-2026-85706, a CVSS 10.0 unauthenticated path traversal flaw in the repository commits API that lets attackers read arbitrary files from self-managed servers. A second critical bug, CVE-2026-87719 (CVSS 9.9), is an insecure deserialization flaw in the GraphQL subscription serializer affecting Enterprise Edition users with Duo Chat access, exposing Advanced Search configuration data and credentials. Security firm watchTowr reported in-the-wild probing almost immediately after disclosure. GitLab.com and GitLab Dedicated are already patched; self-managed installations remain exposed and are urged to upgrade immediately, noting some database migrations may cause downtime. Additional high- and medium-severity fixes address a buffer overflow enabling RCE, CI/CD variable exposure, XSS, DoS bugs, a SAML SSO bypass, and exposed Workhorse credentials.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://devops.com/gitlabs-critical-patch-closes-a-path-traversal-flaw-attackers-are-already-probing>

## Questions this post answers

### What does CVE-2026-85706 in GitLab allow an attacker to do?

CVE-2026-85706 is a CVSS 10.0 unauthenticated path traversal flaw in GitLab's repository commits API that lets an attacker with no credentials read arbitrary files from a self-managed server, including configuration files, tokens, SSH keys, and database credentials. It affects CE and EE versions 18.7 through 19.1.7, 19.2.0 through 19.2.5, and 19.3.0 through 19.3.1.

_Teams tracking actively exploited CVEs like this one can follow patch guidance on daily.dev._

### Which GitLab versions fix the critical September patch vulnerabilities?

GitLab fixed the flaws in versions 19.3.2, 19.2.6, and 19.1.8, released September 10 to address 18 security vulnerabilities including two rated critical. GitLab.com and GitLab Dedicated were already patched automatically, so the risk falls entirely on self-managed installations still running affected releases, some of which may experience downtime from included database migrations during the upgrade.

_Self-managed GitLab admins weighing upgrade timing can track patch details on daily.dev._

### What is CVE-2026-87719 in GitLab and who can exploit it?

CVE-2026-87719 is a CVSS 9.9 insecure deserialization bug in GitLab's GraphQL subscription serializer, affecting Enterprise Edition only. It requires an authenticated user with GitLab Duo Chat access, who can submit a crafted GraphQL subscription argument to extract Advanced Search configuration data and credentials from the system.

_Developers assessing GraphQL and AI-assistant attack surface can dig into security writeups on daily.dev._

---

Tags: [#security](https://daily.dev/tags/security), [#cicd](https://daily.dev/tags/cicd), [#graphql](https://daily.dev/tags/graphql), [#gitlab](https://daily.dev/tags/gitlab)

[View this post on daily.dev](https://daily.dev/posts/gitlab-s-critical-patch-closes-a-path-traversal-flaw-attackers-are-already-probing-tmn6i0kaw)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"GitLab’s Critical Patch Closes a Path Traversal Flaw Attackers Are Already Probing","url":"https://daily.dev/posts/gitlab-s-critical-patch-closes-a-path-traversal-flaw-attackers-are-already-probing-tmn6i0kaw","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/gitlab-s-critical-patch-closes-a-path-traversal-flaw-attackers-are-already-probing-tmn6i0kaw"},"datePublished":"2026-09-14T08:21:42.038Z","dateModified":"2026-09-14T21:35:03.644Z","description":"GitLab shipped a critical patch (versions 19.3.2, 19.2.6, 19.1.8) on September 10 fixing 18 security vulnerabilities, including CVE-2026-85706, a CVSS 10.0...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1c5d747e207dad40f78713d311cfd312?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1c5d747e207dad40f78713d311cfd312?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"DevOps.com","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"DevOps.com","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/db8f2265cff0416c878c6e7e92bb8715","url":"https://daily.dev/sources/devops"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/gitlab-s-critical-patch-closes-a-path-traversal-flaw-attackers-are-already-probing-tmn6i0kaw","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cicd,graphql,gitlab","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"DevOps.com","item":"https://daily.dev/sources/devops"},{"@type":"ListItem","position":3,"name":"GitLab’s Critical Patch Closes a Path Traversal Flaw Attackers Are Already Probing"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/gitlab-s-critical-patch-closes-a-path-traversal-flaw-attackers-are-already-probing-tmn6i0kaw#faq","mainEntity":[{"@type":"Question","name":"What does CVE-2026-85706 in GitLab allow an attacker to do?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-85706 is a CVSS 10.0 unauthenticated path traversal flaw in GitLab's repository commits API that lets an attacker with no credentials read arbitrary files from a self-managed server, including configuration files, tokens, SSH keys, and database credentials. It affects CE and EE versions 18.7 through 19.1.7, 19.2.0 through 19.2.5, and 19.3.0 through 19.3.1. Teams tracking actively exploited CVEs like this one can follow patch guidance on daily.dev."}},{"@type":"Question","name":"Which GitLab versions fix the critical September patch vulnerabilities?","acceptedAnswer":{"@type":"Answer","text":"GitLab fixed the flaws in versions 19.3.2, 19.2.6, and 19.1.8, released September 10 to address 18 security vulnerabilities including two rated critical. GitLab.com and GitLab Dedicated were already patched automatically, so the risk falls entirely on self-managed installations still running affected releases, some of which may experience downtime from included database migrations during the upgrade. Self-managed GitLab admins weighing upgrade timing can track patch details on daily.dev."}},{"@type":"Question","name":"What is CVE-2026-87719 in GitLab and who can exploit it?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-87719 is a CVSS 9.9 insecure deserialization bug in GitLab's GraphQL subscription serializer, affecting Enterprise Edition only. It requires an authenticated user with GitLab Duo Chat access, who can submit a crafted GraphQL subscription argument to extract Advanced Search configuration data and credentials from the system. Developers assessing GraphQL and AI-assistant attack surface can dig into security writeups on daily.dev."}}]}
```

