logo

CVE-2026-19478 (CVSS 9.4): GitLab GraphQL Code Injection Flaw Patched

ID: 03cd684d-6edc-59a7-bd5e-a3ae30c715bd

STIX ID: report--03cd684d-6edc-59a7-bd5e-a3ae30c715bd

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-08-18

Date Updated: 2026-08-18

Author: Do Son

...
...

GitLab released an out-of-band critical patch on 2026-08-17 to fix two GraphQL-related vulnerabilities — CVE-2026-19478 (unauthenticated code injection, CVSS 9.4) that can modify or delete public project data, and CVE-2026-19650 (CSRF, CVSS 7.1); self-managed instances must upgrade to the listed fixed versions immediately while GitLab.com and Dedicated customers are already protected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.