GitLab Unauthenticated Path Traversal via GitLab Commits API (CVE-2026-85706)
Detects unauthenticated path traversal attempts targeting the GitLab repository commits API, specifically checking for URL-encoded and plain path traversal patterns (e.g., '../') in requests to the commits endpoint. This behavior is indicative of attempts to exploit vulnerabilities like CVE-2026-85706 to read arbitrary files outside the repository scope.
Microsoft Sentinel (KQL)

