PT-2026-76768 · Gitlab · Gitlab
CVE-2026-19478
·
Published
2026-08-17
·
Updated
2026-09-02
CVSS v3.1
9.7
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GitLab CE/EE versions 18.2 through 18.11.10
GitLab CE/EE versions 19.0 through 19.0.7
GitLab CE/EE versions 19.1 through 19.1.5
GitLab CE/EE versions 19.2 through 19.2.3
Description
An unauthenticated remote attacker can modify or delete public projects and user data through a code injection flaw. The issue stems from incorrect code generation management and a specially crafted GraphQL directive that bypasses standard field processing logic to affect server-side objects. This flaw has been observed under active exploitation in the wild. The attack requires HTTP(S) access to the GraphQL API endpoint.
Recommendations
Update GitLab CE/EE versions 18.2 through 18.11.10 to version 18.11.11 or newer.
Update GitLab CE/EE versions 19.0 through 19.0.7 to version 19.0.8 or newer.
Update GitLab CE/EE versions 19.1 through 19.1.5 to version 19.1.6 or newer.
Update GitLab CE/EE versions 19.2 through 19.2.3 to version 19.2.4 or newer.
Restrict access to the GraphQL API for untrusted sources using a reverse proxy, WAF, or VPN.
Limit GitLab access from external networks as a temporary measure.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab