PT-2026-76769 · Gitlab · Gitlab
CVE-2026-19650
·
Published
2026-08-17
·
Updated
2026-08-27
CVSS v2.0
9.7
High
| Vector | AV:N/AC:L/Au:N/C:P/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GitLab CE/EE versions 18.2 through 18.11.10
GitLab CE/EE versions 19.0 through 19.0.7
GitLab CE/EE versions 19.1 through 19.1.5
GitLab CE/EE versions 19.2 through 19.2.3
Description
Improper request validation in GraphQL multiplex query handling allows an unauthenticated user to execute mutations via GET requests. This issue involves Cross-Site Request Forgery (CSRF), a technique where a malicious actor tricks a user's browser into performing an unwanted action on a different website. In some cases, this could lead to remote code execution by sending specially crafted GET requests.
Recommendations
Update GitLab CE/EE versions 18.2 through 18.11.10 to version 18.11.11.
Update GitLab CE/EE versions 19.0 through 19.0.7 to version 19.0.8.
Update GitLab CE/EE versions 19.1 through 19.1.5 to version 19.1.6.
Update GitLab CE/EE versions 19.2 through 19.2.3 to version 19.2.4.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab