Tag: cve 2026 19478
1 article

GitLab Patches Flaw That Exposes Public Projects to Unauthenticated Deletion
GitLab has urgently patched a critical vulnerability that left public projects open to deletion by anyone, with no login required - a flaw that scored a near-perfect 9.4 on the severity scale. The fix addresses a GraphQL weakness that could let unauthenticated users remotely modify or delete public projects and user data.