CVE Tools

Критическая уязвимость в GitLab позволяла удалять общедоступные проекты

Хакер (xakep.ru)By Мария Нефёдова

PatchGitLab

Our summary

GitLab has released emergency patches for Community Edition and Enterprise Edition to address CVE-2026-19478, a critical vulnerability scored 9.4 on the CVSS scale. This flaw allowed unauthenticated attackers to remotely modify or delete public projects and user data via a specific GraphQL directive without requiring any user interaction. The issue affects all versions from 18.2 through 18.11.11, branch 19.0 up to 19.0.8, branch 19.1 up to 19.1.6, and 19.2 up to 19.2.4. Self-managed administrators are urged to update immediately to one of the fixed releases: 19.2.4, 19.1.6, 19.0.8, or 18.11.11, while users of GitLab.com and Dedicated instances require no action.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store