GitLab fixes critical code injection vulnerability

GitLab fixes critical code injection vulnerability

GitLab on Monday deployed patches for two vulnerabilities, including a critical code injection flaw that can be exploited without authentication.

The vulnerability, tracked as CVE-2026-19478 (CVSS score 9.4), allows attackers to modify or delete user data and public projects via a GraphQL statement, GitLab explains in its advisory.

The second bug is CVE-2026-19650 (CVSS score of 7.1), a Cross-Site Request Forgery (CSRF) issue that affects the GraphQL multiplex query handler.

“GitLab fixed an issue that could have allowed an unauthenticated user to perform mutations via GET requests under certain conditions due to improper request validation in GraphQL’s multiplexed query processing,” the advisory said.

The two vulnerabilities affect all versions of the GitLab Community Edition (CE) and Enterprise Edition (EE) from 18.2, 19.0, 19.1 and 19.2. They have been fixed in GitLab CE/EE versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4.

“We strongly recommend that all self-managed GitLab installations immediately update to one of these versions,” GitLab notes.

Advertising. Scroll to continue reading.

The patches were automatically applied to GitLab.com and GitLab Dedicated and no action is required from users.

According to GitLab, both security flaws were reported via the HackerOne bug bounty program. The code management and sharing platform makes no mention of any of these vulnerabilities being exploited in the wild.

Related: Dozens of WebKit vulnerabilities fixed with new security updates for macOS and iOS

Related: Other news: Rapid7 layoffs, hacking of a Boeing 737, cooling system vulnerabilities

Related: Is patching dead? Vulnerability management in the post-myth era

Related: WordPress 7.0.4 fixes remote code execution vulnerability

Leave a Reply

Your email address will not be published. Required fields are marked *