Patch released GitLab CE/EE rce GitLab web-app
Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
CVE Tools coverage
GitLab has deployed urgent fixes for two security issues affecting Community Edition and Enterprise Edition versions prior to specific release thresholds. The primary concern is a critical vulnerability identified as CVE-2026-19478">CVE-2026-19478, which enables unauthenticated remote attackers to execute code via a GraphQL directive, potentially compromising public project integrity and user data. A secondary high-severity flaw, CVE-2026-19650">CVE-2026-19650, involves cross-site request forgery risks within the GraphQL multiplex query handler.
Self-managed instances must be updated immediately to versions 18.11.11, 19.0.8, 19.1.6, or 19.2.4 to mitigate these risks, while hosted GitLab.com and Dedicated environments are already protected.