TUGitLab Maintenance

Today, September 29, 2026, at 3:00 p.m., the GitLab master key will be rotated.

Impact:

  • All existing API keys will become invalid
  • All Personal Access Tokens will lose validity
  • All GitLab Runner tokens must be renewed
  • Deploy tokens, CI/CD variables, and secrets are affected
  • Any stored SSH keys should also be rotated

Action required:

  1. Please prepare to reconfigure your access credentials
  2. After 15:00, all tokens and keys must be recreated and redeployed
  3. Check your CI/CD pipelines for broken connections
  4. Rotate all sensitive credentials that were managed through GitLab

Background:
The CVE-2026-85706 vulnerability affects the Repository Commits API and is being actively exploited. As a precautionary measure, we are rotating all potentially compromised credentials, even though we have not detected any concrete compromise.

We appreciate your understanding of these necessary security measures. Please contact the GitLab team if you have any questions.

Best regards,
GitLab Team – CIT – TU Wien