Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
4 results for “path traversal”
Maximum Severity GitLab Flaw Puts Supply Chains at Risk
A critical path traversal vulnerability (CVE-2026-85706) with a maximum CVSS score of 10.0 has been disclosed in GitLab CE and EE, enabling unauthorized file system access that could compromise software supply chains.
Sep 15, 2026
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab patched a critical CVSS 10.0 path traversal vulnerability (CVE-2026-85706) in its repository commits API that enabled unauthenticated remote file reading, with evidence of active exploitation attempts observed within hours of disclosure.
Sep 11, 2026
GitLab urges users to patch max severity path traversal flaw
GitLab disclosed and urged immediate patching of a critical path traversal vulnerability (CVE-2026-85706) that could allow unauthorized file system access on affected servers.
Sep 11, 2026
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
A high-severity unauthenticated path traversal vulnerability (CVE-2026-29059, CVSS 7.5) in Windmill’s get_log_file endpoint is actively exploited in the wild, enabling attackers to read arbitrary server files without authentication.
Jul 22, 2026