← Back to the CVE Tracker
GitLab has released emergency patches for two high-severity vulnerabilities, including one with a critical CVSS score of 10.0 that allows unauthenticated attackers to read any file on a server. A second vulnerability, rated 9.9, enables authenticated users to potentially access sensitive settings and passwords. Security researchers have already observed internet-wide probes targeting the critical file-reading flaw, urging self-managed GitLab users to update immediately.