- Description
- GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.
- Source
- cve@gitlab.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 7.1
- Impact score
- 4.2
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
- Severity
- HIGH
- cve@gitlab.com
- CWE-352
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
1
🚨 One GraphQL Directive. Two GitLab CVEs. CVE-2026-19478 (9.4): unauthenticated users can modify/delete public projects + user data CVE-2026-19650 (7.1): CSRF can execute mutations using a logged-in user’s session FULL REPORT: https://t.co/x7O2xXHq0l -- #CyberSecurity #C
@OX__Security
18 Aug 2026
340 Impressions
2 Retweets
8 Likes
0 Bookmarks
0 Replies
0 Quotes
GitLab patches two vulnerabilities in CE and EE. CVE-2026-19478 (CVSS 9.4) permits unauthenticated code injection via GraphQL directives to alter or delete public projects. CVE-2026-19650 (CVSS 7.1) enables CSRF through insufficient GraphQL multiplex query validation. Upgrade
@WorldCyberNewsX
18 Aug 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
GitLabに重大(Critical)な脆弱性。CVE-2026-19478はCVSSスコア9.4で、GraphQL経由で無認証で公開リポジトリを削除可能なもの。具体的に脆弱なディレクティブは非開示。GraphQLにおけるSSRFのCVE-2026-19650と併せ修正。 https://t
@__kokumoto
17 Aug 2026
703 Impressions
0 Retweets
2 Likes
2 Bookmarks
0 Replies
0 Quotes