CVE Tools

Critical and High-Severity GraphQL CVEs in GitLab: Code Injection and CSRF via One Directive

OX SecurityBy Nir Zadok, Moshe Siman Tov Bustan6 min read

PatchGitLab CE/EE

Our summary

GitLab released version 19.2.4, along with updates for older branches, to address two significant vulnerabilities in its GraphQL API. The primary issue, CVE-2026-19478, is a critical code injection flaw that enables unauthenticated attackers to modify or delete public project and user data by exploiting a specific directive. Additionally, CVE-2026-19650 allows cross-site request forgery attacks against logged-in users through improper validation of multiplexed queries. Self-managed instances running versions between 18.2 and 19.2 should upgrade immediately to the latest patched releases.

Read at OX Security

Below is the opening; the full story is at OX Security.

From OX Security

Two flaws in GitLab’s GraphQL API: one lets any user wipe or alter public projects and user data, the other quietly runs changes using a logged-in user’s own permissions. Self-managed instances from 18.2 through 19.2 need to upgrade now.

Overview

On August 17, 2026, GitLab published 19.2.4, 19.1.6, 19.0.8, and 18.11.11, fixing two critical GraphQL vulnerabilities.…

Continue at OX Security

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store