Our GitLab instance was affected by the vulnerability identified as CVE-2026-85706. The vulnerability has now been fully remediated. Our investigation has found no evidence of deep intrusion, unauthorized access to our databases, or persistent attacker access to our systems. We have already rotated the most sensitive credentials.
- Revoke all Personal Access Tokens
- Revoke runner authentication/registration tokens and unregister current runners
- Invalidate all active sessions
- Clear values from affected protected/masked CI/CD variables
- Clear webhook secret tokens
- Clear credentials used by third-party integrations such as Slack, Jira, ...
For CI/CD variables, webhook secrets, and third-party integrations, the configuration will remain in place, but the secret values will be emptied.
After the maintenance, please:
- Sign in again
- Recreate Personal Access Tokens
- Re-register your runners
- Rotate and set required CI/CD, webhook, and integration secrets that you manage
Projects currently identified as impacted by CI/CD secret clearing: datamite-project, oniro-core, oniro-compliancetoolchain, moasico, nemo, datamite, codeco, hyper-ai, enact, dash, papyrus, and personal projects forked.
If you need help restoring your configuration, please contact us via the
Helpdesk.