< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

3 clusters · 9 sources · 25 days · First seen · Last updated

GitLab security vulnerability disclosures

Overview

GitLab has addressed two significant security vulnerabilities involving remote code execution and unauthorized data modification.

In July 2026, researchers identified a critical flaw in the native C-based Ruby JSON parser, Oj. This vulnerability allowed attackers to achieve remote code execution by exploiting GitLab’s handling of Jupyter Notebook (.ipynb) files. The issue, which had existed since July 2022, was addressed via a patch released in June 2026 that fixed an unchecked nesting-stack overflow and an unsafe key-length narrowing issue.

In August 2026, GitLab issued urgent updates for a separate critical GraphQL vulnerability, tracked as CVE-2026-19478. This flaw, assigned a CVSS score of 9.4 out of 10, involves a GraphQL directive that could allow unauthenticated attackers to modify or delete public projects, rewrite data, forge merge records, and ban project maintainers. The vulnerability affects various versions of both Community Edition (CE) and Enterprise Edition (EE) across the 18.x and 19.x release branches.

While GitLab.com and GitLab Dedicated were patched automatically, administrators of self-managed instances were urged to upgrade to versions 19.2.4, 19.1.6, 19.0.8, or 18.11.11. Although no exploitation had been reported as of August 18, security firm watchTowr reported by August 20 that the vulnerability was being actively exploited in the wild. The firm noted that attackers may be using AI to accelerate the time between disclosure and exploitation.

Entities

GitLab · Open Defense Initiative · WatchTowr · Yuhang Wu · Depthfirst

Timeline

  1. 22 days ago

    [TECHNOLOGY] 4 sources
    GitLab critical vulnerability actively exploited in the wild

    A critical GitLab vulnerability (CVE-2026-19478) is being actively exploited, allowing unauthenticated attackers to modify or delete public projects via GraphQL injection.

  2. 25 days ago

    [TECHNOLOGY] 5 sources
    GitLab patches critical GraphQL vulnerability

    GitLab released critical patches for a GraphQL vulnerability (CVE-2026-19478) that allows unauthenticated attackers to delete or modify public projects and user data.

  3. about 2 months ago

    [TECHNOLOGY] 3 sources
    GitLab patches critical remote‑code‑execution flaw in Oj JSON parser

    Researchers chained two memory‑safety bugs in the Oj JSON parser to achieve remote code execution via Jupyter notebook diffs in GitLab; a patch was issued on June 10, 2026 but initially mis‑classified, delaying

Sources

bitnewsbot.com · countryrebel.com · cybernoz.com · cybersecuritynews.com · horizon3.ai · saferworld.org.uk · securityaffairs.com · thehackernews.com · tomshw.it

This summary has been updated 1 time: see revision history