Vulnerabilities

GitLab Patches Critical Code Injection Vulnerability

The security defect allows unauthenticated attackers to modify or delete user data and public projects.

GitLab

GitLab on Monday rolled out patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication.

Tracked as CVE-2026-19478 (CVSS score of 9.4), the security defect allows attackers to modify or delete user data and public projects via a GraphQL directive, GitLab explains in its advisory.

The second bug is CVE-2026-19650 (CVSS score of 7.1), a cross-site request forgery (CSRF) issue impacting the GraphQL multiplex query handler.

“GitLab has remediated an issue that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling,” the advisory reads.

The two vulnerabilities impact all GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2, 19.0, 19.1, and 19.2 onwards. They were addressed in GitLab CE/EE versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4.

“We strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately,” GitLab notes.

Advertisement. Scroll to continue reading.

The patches were automatically applied to GitLab.com and GitLab Dedicated, and no action is required from their users.

GitLab says both security defects were reported via its HackerOne bug bounty program. The code management and sharing platform makes no mention of any of these vulnerabilities being exploited in the wild.

Related: Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates

Related: In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

Related: Is Patching Dead? Vulnerability Management in the Post-Mythos Era

Related: WordPress 7.0.4 Patches Remote Code Execution Vulnerability

Related Content

Vulnerabilities

The bugs could lead to authentication bypass, shell command execution, and memory corruption.

Vulnerabilities

Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction.

Artificial Intelligence

Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.

Vulnerabilities

WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS.

Vulnerabilities

Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772.

Vulnerabilities

Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox.

Vulnerabilities

Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries. 

Cybercrime

The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version