GitLab Patches Critical Unauthenticated GraphQL Vulnerability
ID: 05fe6ef7-d42e-5afd-aabe-57f3c31de74b
STIX ID: report--05fe6ef7-d42e-5afd-aabe-57f3c31de74b
Feed Name: Security Affairs
Threat Score
GitLab released emergency patches addressing a critical unauthenticated GraphQL vulnerability (CVE-2026-19478, CVSS 9.4) that could let remote attackers modify or delete public projects on self-managed servers and a separate CSRF issue (CVE-2026-19650, CVSS 7.1); administrators should upgrade to the listed patched versions immediately because some 18.x branches remain unpatched and no in-the-wild exploitation has been reported yet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
