Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
[eclipse.org-committers] GitLab Security Maintenance Following CVE-2026-85706

Dear Committers,

Our GitLab instance was affected by the vulnerability identified as CVE-2026-85706. The vulnerability has now been fully remediated. Our investigation has found no evidence of deep intrusion, unauthorized access to our databases, or persistent attacker access to our systems. We have already rotated the most sensitive credentials. 

As an additional precaution, maintenance is scheduled for Friday, September 18 at 9:00am CEST. During this operation, we plan to take the following actions:
  • Revoke all Personal Access Tokens
  • Revoke runner authentication/registration tokens and unregister current runners
  • Invalidate all active sessions
  • Clear values from affected protected/masked CI/CD variables
  • Clear webhook secret tokens
  • Clear credentials used by third-party integrations such as Slack, Jira, ...
For CI/CD variables, webhook secrets, and third-party integrations, the configuration will remain in place, but the secret values will be emptied.

After the maintenance, please:
  • Sign in again
  • Recreate Personal Access Tokens 
  • Re-register your runners 
  • Rotate and set required CI/CD, webhook, and integration secrets that you manage
Projects currently identified as impacted by CI/CD secret clearing: datamite-project, oniro-core, oniro-compliancetoolchain, moasico, nemo, datamite, codeco, hyper-ai, enact, dash, papyrus, and personal projects forked.

If you need help restoring your configuration, please contact us via the Helpdesk.

Kind regards,

Sébastien Heurtematte
Security Software Engineer | Eclipse Foundation 
💬@sebastien.heurtematte:matrix.eclipse.org

Eclipse Foundation: The Community for Open Collaboration and Innovation



Back to the top