GitLab released emergency security fixes for a critical flaw that could let an unauthenticated attacker modify or delete user data and public projects on affected self-managed servers. The issue, CVE-2026-19478 (CVSS 9.4), is a code-injection bug in a GraphQL directive; GitLab also fixed CVE-2026-19650, a GraphQL multiplex query handler cross-site request forgery flaw. Affected GitLab CE and EE branches include 18.2+, 19.0, 19.1, and 19.2, with fixes in 18.11.11, 19.0.8, 19.1.6, and 19.2.4.
Why it matters: Organizations running self-managed GitLab should treat this as urgent because the most serious flaw does not require an attacker to log in first. Upgrade immediately to a fixed version; GitLab.com and GitLab Dedicated users do not need to take action.
info@thehackernews.com (The Hacker News)
2026.08.21
98% relevant
This updates the same CVE-2026-19478 event with the key development that attackers began exploiting the flaw within days of disclosure, increasing urgency for organizations running self-managed GitLab CE and EE.
Ionut Arghire
2026.08.20
96% relevant
This article updates the same CVE-2026-19478 event with new evidence that exploitation attempts began roughly two days after disclosure, based on WatchTowr honeypots, and adds concrete detection guidance to hunt for requests containing '@gl_introduced'.
Ionut Arghire
2026.08.18
100% relevant
This article appears to be the initial report of GitLab's August 18, 2026 disclosure and patch release for CVE-2026-19478 and CVE-2026-19650.
← Back to all stories