CVE-2026-19478 — a critical GraphQL vulnerability rated 9.4 under the CVSS scale — can, GitLab says, "under certain conditions allow an unauthenticated user to remotely modify or delete public projects and user data."
What GitLab released on August 17, 2026
On August 17, 2026, GitLab published a critical security patch addressing two GraphQL-related vulnerabilities in its Community Edition (CE) and Enterprise Edition (EE). The headline flaw is tracked as CVE-2026-19478 and carries a Critical rating and a CVSS score of 9.4. A second issue, CVE-2026-19650, is rated High with a CVSS score of 7.1 and concerns a cross-site request forgery (CSRF) weakness in the GraphQL multiplex query handler.
GitLab described the first fix this way: "GitLab has remediated an issue that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive." The company noted that it has not named the GraphQL directive involved nor specified the precise conditions necessary for exploitation.
Affected versions and who must act
GitLab said only self-managed installations need to act; hosted services are already patched. "GitLab.com and GitLab Dedicated are already running the patched version. GitLab.com and GitLab Dedicated customers do not need to take action," the company said.
The fixed builds are available as GitLab 19.2.4, 19.1.6, 19.0.8, and 18.11.11. The vendor listed affected ranges as:
- All versions from 18.2 before 18.11.11
- 19.0 before 19.0.8
- 19.1 before 19.1.6
- 19.2 before 19.2.4
GitLab emphasized that the fixes do not extend to the 18.2 through 18.10 branches, which fall inside the affected range.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadTechnical character and disclosure timing
The CVE-2026-19478 vector published by GitLab indicates the flaw can be exploited over a network by an attacker holding no credentials and without any action on the part of a victim. By contrast, the CSRF-related CVE-2026-19650 "requires user interaction to work," GitLab said, and described it in full as: "GitLab has remediated an issue that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling."
GitLab also said the release introduces no new migrations and is not expected to require downtime on multi-node deployments.
The advisory discloses no confirmed exploitation of either flaw, and as of August 18, 2026 there was no public exploit code on GitHub for these issues. GitLab did not immediately respond to a request for comment.
Context: recent activity around GitLab vulnerabilities
The August 17 disclosure follows a July 2026 report in which researchers published working exploit code for a separate GitLab flaw affecting self-managed servers. GitLab said it will make the issues detailing each vulnerability public on its issue tracker 90 days after the release that patched them; the company’s June 10, 2026 patch release previously used a 30-day window. That 90-day timetable places the publication of technical details for CVE-2026-19478 and CVE-2026-19650 around mid‑November 2026.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: If you operate self-managed GitLab installations, apply the patches to the listed versions immediately, upgrading to 19.2.4, 19.1.6, 19.0.8, or 18.11.11 as appropriate. Hosted customers on GitLab.com or GitLab Dedicated do not need to take action, GitLab said.
- Procurement and enterprise IT leaders: Confirm whether your deployments are self-managed or hosted; the vendor has separated responsibilities clearly — GitLab.com and GitLab Dedicated are already patched, while self-managed servers remain the point of exposure.
- End users of public projects: Until affected self‑managed servers are patched, the company’s advisory implies there is potential for modification or deletion of public projects and user data via the described GraphQL flaw, so organizations should monitor project integrity and backups on self-managed instances.
GitLab pushed this critical update outside its usual cadence — the company normally issues twice-monthly updates on the second and fourth Wednesdays — releasing the patch five days after a routine update that carried no critical-rated issues. That urgency, the vendor’s decision to withhold detailed technical disclosure for 90 days, and the recent publication of exploit code for a different self-managed flaw together make this an event self‑managed administrators cannot afford to defer.
Original reporting: https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html




