GitLabCVE-2026-19478
GitLab: code injection
Critical9.4CVE-2026-19478 · Published Aug 17, 2026 · updated Sep 2, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GitLab Product | >= 18.2, < 18.11.11 | 18.11.11 |
| >= 19.0, < 19.0.8 | 19.0.8 | |
| >= 19.1, < 19.1.6 | 19.1.6 | |
| >= 19.2, < 19.2.4 | 19.2.4 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-94
More GitLab advisories
All GitLab| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | GitLab: cross-site request forgery | High7.1 | 18.11.11+3 more |
| Aug 12 | GitLab: missing authorization | Medium4.3 | 19.0.6+2 more |
| Aug 12 | GitLab: missing authorization | Medium4.3 | 19.0.6+2 more |
| Aug 12 | GitLab: improper authorization | High8.5 | 19.1.4+1 more |
| Aug 12 | GitLab: improper authorization | Medium4.3 | 19.1.4+1 more |
| Aug 12 | GitLab: missing authorization | High7.1 | 19.1.4+1 more |