PT-2026-76769 · Gitlab · Gitlab

CVE-2026-19650

·

Published

2026-08-17

·

Updated

2026-08-27

CVSS v2.0

9.7

High

VectorAV:N/AC:L/Au:N/C:P/I:C/A:C
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 18.2 through 18.11.10 GitLab CE/EE versions 19.0 through 19.0.7 GitLab CE/EE versions 19.1 through 19.1.5 GitLab CE/EE versions 19.2 through 19.2.3
Description Improper request validation in GraphQL multiplex query handling allows an unauthenticated user to execute mutations via GET requests. This issue involves Cross-Site Request Forgery (CSRF), a technique where a malicious actor tricks a user's browser into performing an unwanted action on a different website. In some cases, this could lead to remote code execution by sending specially crafted GET requests.
Recommendations Update GitLab CE/EE versions 18.2 through 18.11.10 to version 18.11.11. Update GitLab CE/EE versions 19.0 through 19.0.7 to version 19.0.8. Update GitLab CE/EE versions 19.1 through 19.1.5 to version 19.1.6. Update GitLab CE/EE versions 19.2 through 19.2.3 to version 19.2.4.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11880
BIT-GITLAB-2026-19650
CVE-2026-19650

Affected Products

Gitlab