CVE-2026-19478: GitLab GraphQL Flaw Exploited
ID: 8019e3aa-f877-5376-a9bb-61c90103f8f7
STIX ID: report--8019e3aa-f877-5376-a9bb-61c90103f8f7
Feed Name: SOCRadar Blog
GitLab patched CVE-2026-19478, a critical (CVSS 9.4) GraphQL code-injection vulnerability in self-managed CE/EE that can enable unauthenticated attackers to modify or delete public projects and user data; fixed releases (18.11.11, 19.0.8, 19.1.6, 19.2.4) are provided, exploitation attempts were observed in the wild, and defenders are advised to immediately patch affected instances, restrict unauthenticated access to /api/graphql if needed, inspect logs for @gl_introduced GraphQL queries, and validate backups and repository integrity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
