Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
gitlab-cve-2026-85706-ioc — CVE-2026-85706 — GitLab Path Traversal IOC Scanner & Detection Toolkit. Detect and hunt for exploitation of the critical unauthenticated GitLab CE/EE path traversal vulnerability with IOC scanning, Sigma, Suricata/Snort, and SIEM detection rules. | Kitploit
工具/GitHubGitHub/jithinkrishnanrs/gitlab-cve-2026-85706-ioc
Defensive ToolsIndicator of Compromise (IOC) ManagementVulnerability ScannersThreat Feeds & AggregatorsVulnerability AnalysisInformation GatheringWeb SecurityNetwork Security

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
Threat Intelligence
Incident Response
Log Analysis
GitHubjithinkrishnanrs/gitlab-cve-2026-85706-ioc

gitlab-cve-2026-85706-ioc

CVE-2026-85706 — GitLab Path Traversal IOC Scanner & Detection Toolkit. Detect and hunt for exploitation of the critical unauthenticated GitLab CE/EE path traversal vulnerability with IOC scanning, Sigma, Suricata/Snort, and SIEM detection rules.

查看仓库
15119天前尚未审核
内容在请求的语言中不可用。显示英文版本。

CVE-2026-85706 — GitLab Path Traversal IOC Scanner & Detection Toolkit

GitLab CE/EE Repository Commits API Unauthenticated Path Traversal (CVSS 3.1: 10.0, Critical) Status: Actively exploited in the wild · Listed in CISA KEV (2026-09-11, due 2026-09-14) · Patched by GitLab 2026-09-10

CI License: MIT CVSS CISA KEV GitHub issues GitHub stars

A free, open-source incident response and threat hunting toolkit for CVE-2026-85706 — a critical, unauthenticated path traversal vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) affecting the repository commits API. This repository gives security teams, SOC analysts, detection engineers, and GitLab administrators a ready-to-run IOC (Indicators of Compromise) scanner, Sigma / Suricata / Snort detection rules, Splunk / Elastic / OpenSearch hunting queries, and a step-by-step remediation guide — everything you need to detect exploitation attempts, confirm patch status, and respond to this GitLab zero-day / n-day vulnerability quickly.

🔎 Looking for the fastest path to "am I affected?" Jump to Quick Start.

🚨 Looking for what to patch to? Jump to Fixed Versions & Patch.


Table of Contents

  • Vulnerability Summary
  • Why This Matters
  • Fixed Versions & Patch
  • Related Vulnerabilities Fixed in the Same Release
  • Repository Contents
  • Quick Start
    • 1. Scan your GitLab logs for IOCs
    • 2. Check if your GitLab version is patched
    • 3. Deploy detection rules to your SIEM / IDS
  • How the Scanner Works
  • Sample Output
  • Indicators of Compromise (IOC) Summary
  • Detection Content
  • Remediation
  • Frequently Asked Questions
  • Limitations & Disclaimer
  • Contributing
  • Sources & Further Reading
  • License

Vulnerability Summary

CVE IDCVE-2026-85706
Vendor / ProductGitLab Community Edition (CE) & Enterprise Edition (EE), self-managed
Vulnerability classPath Traversal (CWE-35), part of the broader Improper Limitation of a Pathname family (CWE-22)
Affected componentRepository Commits API (/api/v4/projects/:id/repository/commits...)
Root causeImproper path confinement combined with missing authentication enforcement in the affected API endpoint
Affected versionsGitLab CE/EE 18.7 through 19.1.7, 19.2 through 19.2.5, 19.3 through 19.3.1 (last vulnerable patch on each branch; anything on an older, unsupported branch is presumed vulnerable too)
Authentication requiredNone — unauthenticated, pre-auth exploitation
Attack vectorNetwork, single HTTP POST request to the commits API
CVSS 3.1 score10.0 (Critical) — vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N (Scope Changed, no availability impact — this is a read-only file-disclosure primitive)
ImpactArbitrary file read on the GitLab server — configuration files, secrets, tokens, source code, potentially SSH keys and database credentials
Reported byExternal security researcher (HackerOne handle "s3ntago"), via GitLab's HackerOne bug bounty program
Disclosed / PatchedSeptember 10, 2026 — part of a critical GitLab security release fixing 17–18 vulnerabilities in total, reported variably by different outlets (see Related Vulnerabilities)
Estimated exposureIndependent reporting estimates 20,000+ internet-facing self-managed GitLab instances globally were running an affected version at disclosure
CISA KEVAdded September 11, 2026; federal civilian remediation due September 14, 2026 (3 calendar days); this places CVE-2026-85706 in CISA's highest-risk tier under Binding Operational Directive (BOD) 26-04 ("Prioritizing Security Updates Based on Risk," effective June 10, 2026, superseding BOD 22-01) — the tier reserved for vulnerabilities that are KEV-listed, publicly exposed, automatable, and capable of yielding full system control, which also mandates forensic triage to determine whether a system was already compromised before patching, not just theoretically exposed
Exploitation statusConfirmed active scanning / probing observed in the wild. Reporting on timing varies: watchTowr's initial "Rapid Reaction" write-up is most commonly cited as observing exploitation attempts roughly 24 hours after disclosure, while at least one outlet (citing watchTowr) reports probes beginning within six hours. Either way, the exploitation window from patch to attack was extremely short.
Public PoCNot confirmed publicly available at time of writing
GitLab.com / DedicatedGitLab.com (SaaS) was already patched at disclosure; GitLab Dedicated customers did not need to take action. Only self-managed CE/EE instances require action
Official CISA hunting guidanceCISA and multiple outlets (e.g. The Hacker News) specifically recommend reviewing logs for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ URIs containing a file.Path parameter — this is exactly the detection logic implemented by this repository's scanner and detection rules

An unauthenticated attacker can send a single crafted HTTP POST request to GitLab's repository commits API endpoint (/api/v4/projects/{id}/repository/commits/), supplying a file.Path (also seen documented as file.path / file_path) parameter containing directory-traversal sequences (../, URL-encoded variants, etc.), and have the server return the contents of arbitrary files outside the intended repository directory — including GitLab's own secrets file, database configuration, SSH private keys, and other sensitive server-side data. Because no credentials are required and the request is trivial to construct, GitLab and third-party researchers rate this as maximum severity (CVSS 10.0) and CISA has confirmed active exploitation in the wild.

Why This Matters

下载工具