CVE-2026-19478

Published Aug 17, 2026

Last updated a day ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-19478 is a code injection vulnerability found in the GraphQL API of GitLab Community Edition (CE) and Enterprise Edition (EE). This flaw allows remote, unauthenticated attackers to send specially crafted GraphQL directives to vulnerable instances. The successful exploitation of this vulnerability can lead to the modification or deletion of public projects and associated user data. The attack requires no authentication or user interaction, making it straightforward for any actor with network access to the target instance to exploit. The vulnerability affects self-managed GitLab CE/EE versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. GitLab released patches on August 17, 2026, with fixes available in versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11. GitLab.com and GitLab Dedicated instances are not affected, as they were already patched. The vulnerability was responsibly disclosed by security researcher hiimguardian through the HackerOne bug bounty program.

Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
Source
cve@gitlab.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.4
Impact score
5.5
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Severity
CRITICAL

Weaknesses

cve@gitlab.com
CWE-94

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

5

  1. CyberSignal Daily ✓ · 🛠️ DevSecOps · August 19, 2026 🎯 A CVSS 9.4 vulnerability involving one of the world's major development platforms. GitLab has patched CVE-2026-19478, a critical vulnerability rated CVSS 9.4. GitLab says that under certain conditions an unauth

    @XQOPTRX

    19 Aug 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 CVE-2026-19478: Improper Control of Generation of Code ('Code Injection') in GitLab Critical Vulnerability Alert! GitLab is affected by CVE-2026-19478. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://t.co/UYgPqryQux 🔍 Identify Targets via ZoomEye: F

    @zoomeye_team

    19 Aug 2026

    1565 Impressions

    5 Retweets

    17 Likes

    5 Bookmarks

    1 Reply

    0 Quotes

  3. GitLabの重大な脆弱性により、攻撃者が公開プロジェクトを変更または削除できる(CVE-2026-19478) Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) #HelpNetSecurity (Aug 18) https://t.co/Mzc3f0GW6z

    @foxbook

    19 Aug 2026

    197 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  4. 🚨 One GraphQL Directive. Two GitLab CVEs. CVE-2026-19478 (9.4): unauthenticated users can modify/delete public projects + user data CVE-2026-19650 (7.1): CSRF can execute mutations using a logged-in user’s session FULL REPORT: https://t.co/x7O2xXHq0l -- #CyberSecurity #C

    @OX__Security

    18 Aug 2026

    340 Impressions

    2 Retweets

    8 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-19478 - EXPLOIT CVE-2026-71518 - EXPLOIT CVE-2026-74253 CVE-2026-74843 CVE-2026-47686 ..🧵👇

    @exploitgrid

    18 Aug 2026

    50 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. 🚨 Patch Now | August 18, 2026 Today's vulnerabilities are as follows; - GitLab (CVE-2026-19478, CVSS 9.4) - Zoom for Windows (CVE-2026-53412, CVSS 9.8) - WordPress Forminator Forms (CVE-2026-15748, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG https://t.co/yYzCFkUhrZ

    @CERT_UG

    18 Aug 2026

    120 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. GitLab patches two vulnerabilities in CE and EE. CVE-2026-19478 (CVSS 9.4) permits unauthenticated code injection via GraphQL directives to alter or delete public projects. CVE-2026-19650 (CVSS 7.1) enables CSRF through insufficient GraphQL multiplex query validation. Upgrade

    @WorldCyberNewsX

    18 Aug 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. GitLabに重大(Critical)な脆弱性。CVE-2026-19478はCVSSスコア9.4で、GraphQL経由で無認証で公開リポジトリを削除可能なもの。具体的に脆弱なディレクティブは非開示。GraphQLにおけるSSRFのCVE-2026-19650と併せ修正。 https://t

    @__kokumoto

    17 Aug 2026

    703 Impressions

    0 Retweets

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes