GITLAB released a critical out-of-band patch on August 17, 2026, addressing two vulnerabilities: CVE-2026-19478 (a GraphQL code injection rated CVSS 9.4) and CVE-2026-19650 (a CSRF issue rated CVSS 7.1). The first flaw allows unauthenticated attackers to modify or delete public projects, while the second requires user interaction. Both vulnerabilities affect GitLab CE and EE versions prior to the updated 18.11.11, 19.0.8, 19.1.6, and 19.2.4 versions. Users are urged to upgrade immediately as no exploitation has been reported yet.
GitLab fixes CVE-2026-19478 GraphQL injection and CSRF flaw
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
GitLab fixes CVE-2026-19478 GraphQL injection and CSRF flaw
securityonline.info
-
Critical GitLab GraphQL flaw lets attackers delete public projects
thehackernews.com