CVE-2026-85706 GitLab CE/EE 任意文件读取漏洞
影响未认证攻击者可读取服务器任意文件
GitLab CE/EE 在仓库 commits API 中存在路径限制不当与认证缺失问题,导致未认证用户可在特定条件下读取服务器上的任意文件。该漏洞影响多个 18.7 至 19.3 的版本分支,官方已发布修复版本。
影响范围
GitLab CE/EE 18.7 至 18.11.12 之前、19.0 至 19.0.9 之前、19.1 至 19.1.8 之前、19.2 至 19.2.6 之前、19.3 至 19.3.2 之前的版本。
漏洞详情
漏洞类型为任意文件读取,成因是仓库 commits API 未正确限制文件路径且缺少必要的认证校验。攻击者无需登录即可构造特制请求,绕过路径限制读取服务器上的敏感文件。
利用条件与风险
利用无需认证,攻击面为暴露在互联网的 GitLab 实例,可能导致配置文件、密钥等敏感信息泄露,实战风险极高。
修复建议
建议升级至 18.11.12、19.0.9、19.1.8、19.2.6、19.3.2 或更高版本;临时缓解措施暂无公开信息。
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.