Critical GitLab GraphQL Vulnerability Allow Attackers to Delete Public Projects
Brief
GitLab has released urgent security updates to fix a critical GraphQL vulnerability that could allow unauthenticated attackers to modify or delete public projects and user data remotely.
The issue, tracked as CVE-2026-19478, affects GitLab Community Edition and Enterprise Edition installations across several supported release branches. The vulnerability was addressed in GitLab versions 19.
- 4, 19.
- 6, 19.
- 8, and 18.
- 11, released on August 17, 2026.
GitLab strongly recommends that administrators of self-managed instances upgrade immediately. GitLab. com and GitLab Dedicated have already received the patched version and require no customer action.
GitLab GraphQL Vulnerability
CVE-2026-19478 is a code injection issue involving a GraphQL directive.
