TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/News/GitLab Ships an Emergency Patch for a Critical Unauthenticated Code Injection Flaw
News

GitLab Ships an Emergency Patch for a Critical Unauthenticated Code Injection Flaw

GitLab shipped an out-of-schedule patch for a critical, unauthenticated GraphQL flaw that let attackers modify or delete public projects and user data over the network.

August 18, 2026 3 Min Read
39

GitLab pushed out an emergency patch release on August 17, 2026, just five days after a routine, scheduled update that carried no critical-rated fixes, to close a vulnerability that let unauthenticated attackers modify or delete public projects and user data over the network. GitLab rates the flaw Critical, with a CVSS score of 9.4 out of a maximum 10, according to SecurityWeek and GitLab’s own advisory.

Table Of Content

  • What the severity score actually means here
  • A second, lower-severity bug fixed in the same release
  • Who needs to act

The vulnerability, tracked as CVE-2026-19478, sits in how GitLab’s GraphQL API processes a directive: a modifier that changes how a GraphQL query or mutation runs. “GitLab has remediated an issue that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive,” the company said in its advisory. GitLab has not said which directive is involved or what conditions are required to trigger it.

What the severity score actually means here

The CVSS vector GitLab published for CVE-2026-19478, AV:N/AC:L/PR:N/UI:N, describes an attack that can be launched over the network, needs no special skill or timing, requires no account or credentials, and needs no action from a victim. The impact breakdown explains why GitLab treated it as urgent: high impact on integrity and availability, since an attacker can change or destroy data, but low impact on confidentiality, since the bug is not primarily a data-exposure hole. The Hacker News reports that no public proof-of-concept exploit code had surfaced as of August 18, 2026, and GitLab’s advisory does not claim the flaw has been exploited in the wild.

A second, lower-severity bug fixed in the same release

The same patch also closes CVE-2026-19650, a cross-site request forgery (CSRF) issue in the GraphQL multiplex query handler: the code path that lets a client bundle multiple GraphQL operations into a single request. GitLab rates it High, with a CVSS score of 7.1. Unlike the critical flaw, it requires a victim to interact with something first. GitLab’s advisory describes it as an issue that “could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.” Both vulnerabilities were reported through GitLab’s HackerOne bug bounty program, credited to researchers using the handles hiimguardian and kreep.

Who needs to act

The fixes ship in GitLab Community Edition and Enterprise Edition versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11. Both bugs affect GitLab CE/EE in four separate ranges: 18.2 up to 18.11.11, 19.0 up to 19.0.8, 19.1 up to 19.1.6, and 19.2 up to 19.2.4. GitLab.com and GitLab Dedicated are already running the patched code, so hosted customers do not need to do anything. Self-managed installations are the ones exposed, and GitLab is telling every self-managed administrator to upgrade immediately.

One detail changes the remediation path for older deployments: the fix landed only in 18.11.11 and the three newer minor lines, not as a same-branch patch for every affected version. Installations still running the 18.2 through 18.10 branches, which fall inside the vulnerable range, do not get a patch on their own branch and have to upgrade forward to 18.11.11 or later to close the hole. GitLab says the update introduces no new database migrations and should not require downtime on multi-node deployments.

GitLab’s standard policy, stated on its release notes, is to keep the technical detail behind a patched vulnerability off its public issue tracker for 90 days after the fix ships, giving administrators a window to update before the specifics of an exploit become public. That clock started on August 17, which puts the detailed write-up for both CVE-2026-19478 and CVE-2026-19650 on track for mid-November.

Tags:

CybersecurityDevOps SecurityGitLabVulnerability Management

Share

A technician uses a bench magnifier to inspect a printed circuit board
Previous Post

How to Debug Python Code With a Local AI Agent Using Ollama and pytest

A U.S. Army cyber protection specialist monitors a wall of computer screens showing network defense dashboards during a training exercise
Next Post

OpenAI’s Defender’s Window Turns a Security Wake-Up Call Into a Trust Problem

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026