⚠️CVE-2026-85706 (CVSS 10.0)⚠️ Your GitLab will hand a stranger its files. 😱 No login. No account. An attacker just URL-encodes one letter of commits → %63ommits, and GitLab-Workhorse waves the request through — so a single unauthenticated POST to the repository commits API
@EQST
1 grabs
No comments yet
Say something. You’re first.