GITLAB released a critical out-of-band patch on August 17, 2026, addressing two vulnerabilities: CVE-2026-19478 (a GraphQL code injection rated CVSS 9.4) and CVE-2026-19650 (a CSRF issue rated CVSS 7.1). The first flaw allows unauthenticated attackers to modify or delete public projects, while the second requires user interaction. Both vulnerabilities affect GitLab CE and EE versions prior to the updated 18.11.11, 19.0.8, 19.1.6, and 19.2.4 versions. Users are urged to upgrade immediately as no exploitation has been reported yet.
GitLab fixes CVE-2026-19478 GraphQL injection and CSRF flaw
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
GitLab fixes CVE-2026-19478 flaw allowing attacker deletion
securityonline.info
-
GitLab GraphQL Vulnerability CVE-2026-19478 Actively Exploited
securityaffairs.com
-
Attackers hit GitLab flaw CVE-2026-19478 hours after disclosure
thehackernews.com
-
GitLab Flaw CVE-2026-19478 Exploited in Days, Urges Patch
securityweek.com
-
GitLab flaw (CVE-2026-19478) lets attackers delete projects
darkreading.com
-
GitLab fixes critical code injection and CSRF bugs
securityweek.com
-
GitLab Patches Critical Unauthenticated GraphQL Vulnerability
securityaffairs.com
-
GitLab fixes CVE-2026-19478 GraphQL injection and CSRF flaw
securityonline.info