Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects
ID: bafed766-b815-5fde-b162-b69b9157386e
STIX ID: report--bafed766-b815-5fde-b162-b69b9157386e
Feed Name: The Cyber Express
**Executive Summary:** GitLab released emergency patches addressing two vulnerabilities—CVE-2026-19478 (critical code injection, CVSS 9.4) and CVE-2026-19650 (high-severity CSRF, CVSS 7.1)—affecting multiple CE/EE versions; self-managed installations should be upgraded to the disclosed patched releases immediately to prevent potential unauthenticated modification or deletion of public projects and misuse of GraphQL multiplex queries, although GitLab reports no evidence of in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
