A logged-in GitLab user can abuse the package registry to write files across a self-managed server (CVE-2026-10053, CVSS 8.5). A public test lab just proved the flaw is real. Fix: update self-managed
A logged-in GitLab user can abuse the package registry to write files across a self-managed server (CVE-2026-10053, CVSS 8.5). A public test lab just proved the flaw is real. Fix: update self-managed GitLab to 19.2.2, 19.1.4, or 19.0.6. https:// suriq.io/blog/gitlab-package-r egistry-arbitrary-file-write # CVE # infosec # cybersecurity