CVE-2026-19650

Published Aug 17, 2026

Last updated a month ago

CVSS high 7.1
graphql
API

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-19650 is a vulnerability identified in GitLab Community Edition (CE) and Enterprise Edition (EE) that stems from improper request validation within the GraphQL multiplex query handling mechanism. This flaw allows an unauthenticated user to execute mutations through standard GET requests. The technical root cause lies in the GraphQL server's processing of multiplexed queries, where the validation logic failed to adequately distinguish between data retrieval operations (queries) and state-modifying operations (mutations) when submitted via GET methods. This vulnerability is also characterized as a Cross-Site Request Forgery (CSRF) issue in the GraphQL API. It affects GitLab CE/EE versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.

Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.
Source
cve@gitlab.com
NVD status
Analyzed
Products
gitlab

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.1
Impact score
4.2
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
Severity
HIGH

Weaknesses

cve@gitlab.com
CWE-352

Social media

Hype score
Not currently trending

Configurations