logo

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

ID: 6f580339-b5c0-57bc-b1a8-e5c0ca1f0617

STIX ID: report--6f580339-b5c0-57bc-b1a8-e5c0ca1f0617

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

Author: [email protected] (The Hacker News)

...
...

A critical GitLab vulnerability (CVE-2026-19478, CVSS 9.4) enabling unauthenticated code injection against public projects is being actively exploited in the wild; affected CE/EE versions (18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, 19.2 before 19.2.4) have received patches and organizations are advised to upgrade immediately or restrict access to /api/graphql and remove public repositories as temporary mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.