< Back to situation

[REVISION HISTORY]

GitLab security vulnerability disclosures

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-08-18 09:16 UTC → 2026-08-21 10:21 UTC · added removed

GitLab has addressed two significant security vulnerabilities involving remote code execution and unauthorized data modification. In July 2026, researchers identified a critical flaw in the native C-based Ruby JSON parser, Oj. This vulnerability allowed attackers to achieve remote code execution by exploiting GitLab’s handling of Jupyter Notebook (.ipynb) files. The issue, which had existed since July 2022, was addressed via a patch released in June 2026 that fixed an unchecked nesting-stack overflow and an unsafe key-length narrowing issue. In August 2026, GitLab issued urgent updates for a separate critical GraphQL vulnerability, tracked as CVE-2026-19478. This flaw, assigned a CVSS score of 9.4 out of 10, involves a GraphQL directive that could allow unauthenticated attackers to modify or delete public projects projects, rewrite data, forge merge records, and user data. ban project maintainers. The vulnerability affects various versions of both Community Edition (CE) and Enterprise Edition (EE) across the 18.x and 19.x release branches. While GitLab.com and GitLab Dedicated were patched automatically, administrators of self-managed instances were urged to upgrade to specific secure versions 19.2.4, 19.1.6, 19.0.8, or 18.11.11. Although no exploitation had been reported as of August 18, security firm watchTowr reported by August 20 that the vulnerability was being actively exploited in the wild. The firm noted that attackers may be using AI to mitigate accelerate the risk. time between disclosure and exploitation.

Versions

  1. 2026-08-21 10:21 UTC GitLab security vulnerability disclosures
  2. 2026-08-18 09:16 UTC GitLab security vulnerability disclosures

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.