GitLab has released urgent security updates to fix a critical GraphQL vulnerability that could allow unauthenticated attackers to modify or delete public projects and user data remotely.
The issue, tracked as CVE-2026-19478, affects GitLab Community Edition and Enterprise Edition installations across several supported release branches. The vulnerability was addressed in GitLab versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11, released on August 17, 2026.
GitLab strongly recommends that administrators of self-managed instances upgrade immediately. GitLab.com and GitLab Dedicated have already received the patched version and require no customer action.
GitLab GraphQL Vulnerability
CVE-2026-19478 is a code injection issue involving a GraphQL directive. Under specific conditions, an unauthenticated remote attacker could abuse the flaw to perform unauthorized actions against public GitLab resources.
The potential impact includes modifying or deleting public projects and user data without requiring a valid GitLab account. The vulnerability received a CVSS score of 9.4 out of 10, placing it in the critical severity category.
Its CVSS vector indicates that exploitation is possible over the network, requires low attack complexity, requires no privileges or user interaction, and can cause high impacts on integrity and availability.
This makes exposed, unpatched GitLab servers an attractive target for opportunistic attackers and threat actors looking to disrupt public software development infrastructure.
Affected versions include all GitLab CE and EE releases from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.
Organizations operating any affected release should treat the issue as an emergency patching priority, especially where public projects are enabled. GitLab credited security researcher hiimguardian for reporting the vulnerability through its HackerOne bug bounty program.
Technical details are expected to remain limited until GitLab’s standard disclosure timeline allows the related vulnerability issue to become public.
The security release also fixes CVE-2026-19650, a high-severity cross-site request forgery flaw in GitLab’s GraphQL multiplex query handler.
This issue could allow unauthenticated users to execute GraphQL mutations via GET requests if request validation is improperly handled. The flaw carries a CVSS score of 7.1 and affects the same GitLab version ranges.
For defenders, the primary mitigation is to immediately upgrade to GitLab 19.2.4, 19.1.6, 19.0.8, or 18.11.11, depending on the deployed branch.
GitLab said the updates contain no new database migrations and multi-node deployments should not require downtime. However, default Omnibus update behavior may briefly stop and restart services during reconfiguration.
Security teams should also review GitLab audit logs for unexpected changes to public repositories, deleted projects, altered memberships, suspicious GraphQL activity, and unexplained changes to user data. Internet-facing GitLab instances should be prioritized, as the critical vulnerability can be exploited remotely without authentication.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

