Critical CVE-2026-85706, CVE-2026-60004 — An unauthenticated arbitrary file read in GitLab CE/EE and a remote code execution in Gitea's diffpatch API are both being exploited. Fixed versions: GitLab 19.3.2 / 19.2.6 / 19.1.8 / 19.0.9 / 18.11.12, Gitea 1.27.1.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: If you self-host GitLab or Gitea and it's reachable from the internet, patch today. GitLab's commits API let unauthenticated users read arbitrary files from the server (CVSS 10), which means secrets, tokens, and the database password. Gitea before 1.27.1 allows remote code execution through its diffpatch API by installing Git hooks. Both are on CISA's exploited list.
| CVE-2026-85706 | GitLab CE/EE: commits API path traversal → unauthenticated arbitrary file read. CVSS 10. KEV 2026-09-11 |
|---|---|
| GitLab affected | 18.7–18.11.11, 19.0–19.0.8, 19.1–19.1.7, 19.2–19.2.5, 19.3–19.3.1 |
| GitLab fixed | 19.3.2 · 19.2.6 · 19.1.8 · 19.0.9 · 18.11.12 |
| CVE-2026-60004 | Gitea diffpatch API → Git hook installation → remote code execution. CVSS 9.8. KEV 2026-08-25 |
| Gitea affected / fixed | 1.17 through 1.27.0 → fixed in 1.27.1 |
Under certain conditions, GitLab’s repository commits API failed to confine file paths and failed to enforce authentication, so an anonymous request could read arbitrary files from the GitLab server. On a GitLab instance that includes /etc/gitlab/gitlab-secrets.json (the keys that encrypt CI variables and tokens), gitlab.rb (often with SMTP, LDAP and object-storage credentials), and SSH host keys. With those, an attacker can decrypt every CI/CD secret your pipelines use.
GitLab.com was patched by GitLab. Self-managed instances on 18.7 or later need updating.
Gitea’s diffpatch API (used to apply a patch to a repository through the API) could be abused to install Git hooks, which are scripts Git runs on the server, giving remote code execution as the Gitea user. The bug spans Gitea 1.17 through 1.27.0. Forgejo is a fork of Gitea; check Forgejo’s own advisories for whether and where it was fixed in your version.
# GitLab (Omnibus)
sudo gitlab-rake gitlab:env:info | grep -i "GitLab information" -A3
# or: cat /opt/gitlab/embedded/service/gitlab-rails/VERSION
# Gitea
gitea --version
# Docker: docker exec <container> gitea --version
The version is also shown at /help (GitLab) and in the page footer (Gitea) for logged-in admins.
# GitLab Omnibus (Debian/Ubuntu)
sudo apt update && sudo apt install gitlab-ee # or gitlab-ce
# GitLab / Gitea in Docker Compose: bump the image tag, then
docker compose pull && docker compose up -d
# Gitea binary: download 1.27.1+ from dl.gitea.com, replace the binary, restart
sudo systemctl restart gitea
Take a backup first (gitlab-backup create plus /etc/gitlab; gitea dump for Gitea).
For GitLab, an arbitrary file read means you should assume the server’s secrets were read if it was internet-facing on an affected version:
gitlab.rb (SMTP, LDAP bind, object storage, database).For Gitea, check every repository’s hooks/ directory on disk for scripts you didn’t write, look for new admin users, and review the server for unfamiliar processes or cron jobs.
Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.