GitLab released out-of-band security updates for self-managed Community Edition and Enterprise Edition instances to fix CVE-2026-19478, a critical GraphQL directive flaw that can let an unauthenticated remote attacker modify or delete public projects and user data under certain conditions. The vulnerability, classified as CWE-94 and rated CVSS 9.4, affects versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.
GitLab also fixed CVE-2026-19650, a high-severity cross-site request forgery issue in the GraphQL multiplex query handler that could allow unauthenticated mutation execution via GET requests with user interaction. Patched releases are 19.2.4, 19.1.6, 19.0.8, and 18.11.11; GitLab.com and GitLab Dedicated were already remediated and require no customer action. GitLab urged affected self-managed customers to upgrade immediately, and reporting indicated no disclosed in-the-wild exploitation or public exploit code at the time of release.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
By August 26, 2026, public proof-of-concept exploit code was available for CVE-2026-19478 and CVE-2026-19650. The Dutch NCSC warned that this increased the likelihood of active exploitation and urged organizations to install GitLab's fixes promptly.
The Canadian Centre for Cyber Security published a GitLab security advisory on August 21, 2026 referencing the vulnerabilities and patched releases. The notice highlighted the issue alongside recommendations to review and apply the available updates.
GitLab's CSRF flaw CVE-2026-19650 was published as a CVE record on August 17, 2026. The entry described improper request validation in GraphQL multiplex query handling that could let an unauthenticated attacker execute mutations via GET requests under certain conditions.
GitLab received the new CVE entry for CVE-2026-19478 on August 17, 2026. The entry described a GraphQL directive code injection issue that could let an unauthenticated attacker modify or delete public projects and user data under certain conditions.
On August 17, 2026, GitLab released versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11 for self-managed GitLab Community Edition and Enterprise Edition. The update fixed the critical code injection flaw CVE-2026-19478 and the high-severity CSRF flaw CVE-2026-19650, and GitLab said GitLab.com and GitLab Dedicated were already patched.
WatchTowr reported that it reproduced CVE-2026-19478 within minutes of disclosure and later observed in-the-wild exploitation attempts against the GitLab flaw in its honeypot network. The activity began roughly two days after public disclosure, indicating rapid attacker uptake of the vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
41 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcencsc.nl
Open sourcemeetcyber.net
Open sourcecybersecuritynews.com
Open sourcedocs.gitlab.com
Open sourcelinkedin.com
Open sourcegitlab.com
Open sourcedocs.gitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.