Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
PatchGitLab CE/EEOur summary
GitLab has deployed urgent fixes for two security issues affecting Community Edition and Enterprise Edition versions prior to specific release thresholds. The primary concern is a critical vulnerability identified as CVE-2026-19478">CVE-2026-19478, which enables unauthenticated remote attackers to execute code via a GraphQL directive, potentially compromising public project integrity and user data. A secondary high-severity flaw, CVE-2026-19650">CVE-2026-19650, involves cross-site request forgery risks within the GraphQL multiplex query handler.
Self-managed instances must be updated immediately to versions 18.11.11, 19.0.8, 19.1.6, or 19.2.4 to mitigate these risks, while hosted GitLab.com and Dedicated environments are already protected.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.