CVE
CVE-2026-85706: A CVSS 10 Path Traversal in GitLab's Commits API, Now in CISA's KEV Catalog
CVE-2026-85706, a path traversal flaw in GitLab's commits API, hit CVSS 10.0 and CISA's KEV catalog within a day. But there's one exposure condition that determines whether your instance is actually at risk.