< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

GitLab patches critical GraphQL vulnerability

GitLab has issued urgent security updates to address a critical GraphQL vulnerability, tracked as CVE-2026-19478, which could allow unauthenticated remote attackers to modify or delete public projects and user data. The flaw, which involves a GraphQL directive, has been assigned a CVSS score of 9.4 out of 10.

The vulnerability affects both GitLab Community Edition (CE) and Enterprise Edition (EE) installations. Specifically, it impacts versions 18.2 through 18.11.10, 19.0 through 19.0.7, 19.1 through 19.1.5, and 19.2 through 19.2.3.

GitLab has already patched GitLab.com and GitLab Dedicated, meaning those users require no action. However, administrators of self-managed instances are strongly urged to upgrade immediately to versions 19.2.4, 19.1.6, 19.0.8, or 18.11.11. As of August 18, 2026, there have been no reports of this vulnerability being exploited in the wild.

Entities

GitLab