Patch released GitLab web-app rce
Критическая уязвимость в GitLab позволяла удалять общедоступные проекты
CVE Tools coverage
GitLab has released emergency patches for Community Edition and Enterprise Edition to address CVE-2026-19478, a critical vulnerability scored 9.4 on the CVSS scale. This flaw allowed unauthenticated attackers to remotely modify or delete public projects and user data via a specific GraphQL directive without requiring any user interaction. The issue affects all versions from 18.2 through 18.11.11, branch 19.0 up to 19.0.8, branch 19.1 up to 19.1.6, and 19.2 up to 19.2.4. Self-managed administrators are urged to update immediately to one of the fixed releases: 19.2.4, 19.1.6, 19.0.8, or 18.11.11, while users of GitLab.com and Dedicated instances require no action.