GitLab has released crucial security patches to address two significant vulnerabilities affecting its platform, including a critical code injection flaw. This vulnerability is identified as CVE-2026-19478 and carries a CVSS score of 9.4. It allows unauthorized users to modify or delete user data and public projects through a GraphQL directive. The second vulnerability, CVE-2026-19650, with a CVSS score of 7.1, is a cross-site request forgery issue impacting the GraphQL multiplex query handler. Both vulnerabilities affect all versions of GitLab Community Edition and Enterprise Edition from versions 18.2, 19.0, 19.1, and 19.2 onwards. GitLab has addressed these issues in versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4. The company strongly advises self-managed GitLab installations to upgrade to these versions without delay. Users of GitLab.com and GitLab Dedicated do not need to take any action as the patches have been automatically applied. These vulnerabilities were reported through GitLab's HackerOne bug bounty program. There is currently no evidence of these vulnerabilities being exploited in the wild.