logo

Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects

ID: bafed766-b815-5fde-b162-b69b9157386e

STIX ID: report--bafed766-b815-5fde-b162-b69b9157386e

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-08-19

Date Updated: 2026-08-19

Author: Ashish Khaitan

...
...

**Executive Summary:** GitLab released emergency patches addressing two vulnerabilities—CVE-2026-19478 (critical code injection, CVSS 9.4) and CVE-2026-19650 (high-severity CSRF, CVSS 7.1)—affecting multiple CE/EE versions; self-managed installations should be upgraded to the disclosed patched releases immediately to prevent potential unauthenticated modification or deletion of public projects and misuse of GraphQL multiplex queries, although GitLab reports no evidence of in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.