CVE-2026-19478 (CVSS 9.4): GitLab GraphQL Code Injection Flaw Patched
ID: 03cd684d-6edc-59a7-bd5e-a3ae30c715bd
STIX ID: report--03cd684d-6edc-59a7-bd5e-a3ae30c715bd
Feed Name: securityonline.info
Threat Score
GitLab released an out-of-band critical patch on 2026-08-17 to fix two GraphQL-related vulnerabilities — CVE-2026-19478 (unauthenticated code injection, CVSS 9.4) that can modify or delete public project data, and CVE-2026-19650 (CSRF, CVSS 7.1); self-managed instances must upgrade to the listed fixed versions immediately while GitLab.com and Dedicated customers are already protected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
