Exploited Vulnerabilities Daily
🌐 繁體中文

← 所有新增項目

CVE-2026-85706: GitLab Community Edition and Enterprise Edition

GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.

廠商
GitLab
產品
Community Edition and Enterprise Edition
漏洞
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
加入日期
2026年9月11日
CISA 修補期限(美國聯邦機關)
2026年9月14日
已知用於勒索軟體攻擊
未知
弱點(CWE)
CWE-35

參考資料

本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。

最後更新: · 目錄版本 2026.10.02