GitLab has released crucial security patches to address two significant vulnerabilities affecting its platform, including a critical code injection flaw. This vulnerability is identified as CVE-2026-19478 and carries a CVSS score of 9.4. It allows unauthorized users to modify or delete user data and public projects through a GraphQL directive. The second vulnerability, CVE-2026-19650, with a CVSS score of 7.1, is a cross-site request forgery issue impacting the GraphQL multiplex query handler. Both vulnerabilities affect all versions of GitLab Community Edition and Enterprise Edition from versions 18.2, 19.0, 19.1, and 19.2 onwards. GitLab has addressed these issues in versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4. The company strongly advises self-managed GitLab installations to upgrade to these versions without delay. Users of GitLab.com and GitLab Dedicated do not need to take any action as the patches have been automatically applied. These vulnerabilities were reported through GitLab's HackerOne bug bounty program. There is currently no evidence of these vulnerabilities being exploited in the wild.
GitLab Addresses Critical Vulnerabilities in Latest Security Update
GitLab fixed a critical code injection flaw allowing unauthenticated actors to modify or delete user data and public projects.
Executive Summary
GitLab has patched two critical vulnerabilities, a code injection and a cross-site request forgery flaw, affecting its platform. Users are urged to update their self-managed installations immediately to protect against potential data modification or deletion.
Actionable Insights
- Upgrade all self-managed GitLab installations to the latest patched versions immediately.
- Monitor GitLab installations for any unusual activity that could indicate attempted exploitation.
- Review and enhance GraphQL security measures to prevent similar vulnerabilities in the future.
Original source
securityweek.com


