Search
Find merged stories by title or summary.
Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18. 2 before 18. 11. 11, 19. 0 before 19. 0. 8, 19. 1 before 19. 1. 6, and 19. 2 before 19. 2. 4. The fixes are available in GitLab 19. 2. 4, 19. 1. 6, 19. 0. 8, and 18. 11. 11. “These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded … More → The post Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) appeared first on Help Net Security .
Infosec News Nuggets — August 18, 2026
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects GitLab shipped an out-of-cycle patch for a critical flaw, tracked as CVE-2026-19478 with a CVSS score of 9. 4, that could have let an unauthenticated attacker remotely modify or delete public projects and user data through a GraphQL directive. The fix landed in versions 19. 2. 4, 19. 1. 6, 19. 0. 8, and 18. 11. 11, and only self-managed installations need to take action since GitLab. com and GitLab Dedicated are already running patched code. The same release also closed a lower-severity CSRF weakness in the GraphQL multiplex query handler, and no public exploit code or in-the-wild abuse of either bug has surfaced so far.
GitLab Patches Critical Unauthenticated GraphQL Vulnerability
GitLab patched a critical GraphQL flaw that let unauthenticated attackers remotely modify or delete public projects on self-managed servers. GitLab pushed out an emergency patch this week to address a critical flaw, tracked as CVE-2026-19478 (CVSS score of 9.4), that could let an attacker with zero credentials remotely modify or delete public projects and user data. “GitLab has remediated an issue that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.” reads the advisory . GitLab issued an emergency patch on August 17, five days after its regular update. The vulnerability impacts only self-managed installations, users should upgrade to versions 19. 2. 4, 19. 1. 6, 19. 0. 8, and 18. 11. 11 . There’s a gap worth flagging for anyone still sitting on an older release.
Critical GitLab GraphQL Vulnerability Allow Attackers to Delete Public Projects
GitLab has released urgent security updates to fix a critical GraphQL vulnerability that could allow unauthenticated attackers to modify or delete public projects and user data remotely. The issue, tracked as CVE-2026-19478, affects GitLab Community Edition and Enterprise Edition installations across several supported release branches. The vulnerability was addressed in GitLab versions 19. 2. 4, 19. 1. 6, 19. 0. 8, and 18. 11. 11, released on August 17, 2026. GitLab strongly recommends that administrators of self-managed instances upgrade immediately. GitLab. com and GitLab Dedicated have already received the patched version and require no customer action. GitLab GraphQL Vulnerability CVE-2026-19478 is a code injection issue involving a GraphQL directive.
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on
You've reached the end of current stories for this search.
