GitLab Warns of Active Exploitation of Critical GraphQL Flaw
ID: 1193fa45-2203-5da6-a995-728a6a6f5c5d
STIX ID: report--1193fa45-2203-5da6-a995-728a6a6f5c5d
Feed Name: Security Affairs
GitLab has released an emergency patch for CVE-2026-19478 — a critical (CVSS 9.4) GraphQL directive vulnerability that is being actively exploited in the wild to allow unauthenticated actors to remotely modify or delete public projects on self-managed instances; administrators should urgently upgrade to the patched versions (19.2.4, 19.1.6, 19.0.8, 18.11.11), restrict unauthenticated access to /api/graphql, disable public repositories where possible, and check logs for requests containing '@gl_introduced'.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
