LOCAL EXPLOIT GitLab commits API path traversal (CVE-2026-85706)
Detects attempts to exploit a path traversal vulnerability in the GitLab commits API, specifically targeting the /api/v4/projects/ repository/commits path. The rule monitors for directory traversal patterns such as .. or url-encoded variations in conjunction with file paths, which could allow unauthorized access to files outside the intended directory.
Suricata

