ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
GitLab patched a maximum-severity path traversal flaw, CVE-2026-85706, in its repository commits API that allows unauthenticated attackers to read arbitrary files. The company also fixed a critical insecure deserialization bug, CVE-2026-87719, in GitLab EE. Both issues are fixed in versions 19.3.2, 19.2.6, and 19.1.8.
Tracked by ByteBrief