On a Thursday in September 2026, GitLab disclosed a flaw so fundamental in its severity that it carries the highest possible danger rating — a single, unauthenticated HTTP request is all that separates an attacker from every file on a vulnerable server. The vulnerability, residing in the Commits API, requires no credentials, no insider knowledge, and no sophistication to exploit, placing it among the most democratically dangerous flaws in recent memory. Within hours of disclosure, the internet was already alive with probes, reminding us that in the modern threat landscape, the distance between