Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Self-Hosted Git Under Attack: GitLab CVE-2026-85706 (CVSS 10 File Read) and Gitea CVE-2026-60004 (RCE)

Critical CVE-2026-85706, CVE-2026-60004 — An unauthenticated arbitrary file read in GitLab CE/EE and a remote code execution in Gitea's diffpatch API are both being exploited. Fixed versions: GitLab 19.3.2 / 19.2.6 / 19.1.8 / 19.0.9 / 18.11.12, Gitea 1.27.1.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: If you self-host GitLab or Gitea and it's reachable from the internet, patch today. GitLab's commits API let unauthenticated users read arbitrary files from the server (CVSS 10), which means secrets, tokens, and the database password. Gitea before 1.27.1 allows remote code execution through its diffpatch API by installing Git hooks. Both are on CISA's exploited list.

CVE-2026-85706GitLab CE/EE: commits API path traversal → unauthenticated arbitrary file read. CVSS 10. KEV 2026-09-11
GitLab affected18.7–18.11.11, 19.0–19.0.8, 19.1–19.1.7, 19.2–19.2.5, 19.3–19.3.1
GitLab fixed19.3.2 · 19.2.6 · 19.1.8 · 19.0.9 · 18.11.12
CVE-2026-60004Gitea diffpatch API → Git hook installation → remote code execution. CVSS 9.8. KEV 2026-08-25
Gitea affected / fixed1.17 through 1.27.0 → fixed in 1.27.1

GitLab: CVE-2026-85706

Under certain conditions, GitLab’s repository commits API failed to confine file paths and failed to enforce authentication, so an anonymous request could read arbitrary files from the GitLab server. On a GitLab instance that includes /etc/gitlab/gitlab-secrets.json (the keys that encrypt CI variables and tokens), gitlab.rb (often with SMTP, LDAP and object-storage credentials), and SSH host keys. With those, an attacker can decrypt every CI/CD secret your pipelines use.

GitLab.com was patched by GitLab. Self-managed instances on 18.7 or later need updating.

Gitea: CVE-2026-60004

Gitea’s diffpatch API (used to apply a patch to a repository through the API) could be abused to install Git hooks, which are scripts Git runs on the server, giving remote code execution as the Gitea user. The bug spans Gitea 1.17 through 1.27.0. Forgejo is a fork of Gitea; check Forgejo’s own advisories for whether and where it was fixed in your version.

Am I affected?

# GitLab (Omnibus)
sudo gitlab-rake gitlab:env:info | grep -i "GitLab information" -A3
# or: cat /opt/gitlab/embedded/service/gitlab-rails/VERSION

# Gitea
gitea --version
# Docker: docker exec <container> gitea --version

The version is also shown at /help (GitLab) and in the page footer (Gitea) for logged-in admins.

How to patch

# GitLab Omnibus (Debian/Ubuntu)
sudo apt update && sudo apt install gitlab-ee   # or gitlab-ce

# GitLab / Gitea in Docker Compose: bump the image tag, then
docker compose pull && docker compose up -d

# Gitea binary: download 1.27.1+ from dl.gitea.com, replace the binary, restart
sudo systemctl restart gitea

Take a backup first (gitlab-backup create plus /etc/gitlab; gitea dump for Gitea).

If it was exposed: rotate secrets

For GitLab, an arbitrary file read means you should assume the server’s secrets were read if it was internet-facing on an affected version:

  • Rotate CI/CD variables that hold cloud keys, deploy keys, registry passwords and API tokens.
  • Revoke and reissue personal/project/group access tokens and runner registration tokens.
  • Change passwords stored in gitlab.rb (SMTP, LDAP bind, object storage, database).

For Gitea, check every repository’s hooks/ directory on disk for scripts you didn’t write, look for new admin users, and review the server for unfamiliar processes or cron jobs.

Hardening

  • If only your team uses it, put it behind a VPN (WireGuard, Tailscale) or an authenticating proxy instead of the open internet.
  • Disable public sign-up and require 2FA for all users.
  • Subscribe to GitLab’s security release feed or Gitea’s blog. Both ship fixes frequently.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories