Abstrakter Code als Symbol fuer eine Sicherheitsluecke

GitLab: Critical Flaw Lets Attackers Delete Projects

GitLab has a critical security hole: CVE-2026-19478 (CVSS 9.4) lets unauthenticated remote attackers modify or delete public projects and user data. The flaw is already being actively exploited.

Why the flaw is so dangerous

It is a code injection through a GraphQL directive – with no login, no user interaction and no special configuration required. Attackers can use it to rewrite repositories, forge merge records, ban maintainers and delete entire projects.

Patch now

The bug is fixed in versions 19.2.4, 19.1.6, 19.0.8 and 18.11.11. All self-managed GitLab installations should be updated immediately; GitLab.com and GitLab Dedicated already run the patched version. Attackers began exploiting it roughly two days after disclosure – the flaw was reproducible within minutes. Anyone who has not patched yet should search their web logs for requests containing @gl_introduced.


Sources: Help Net Security, SecurityWeek.

Mastodon
Scroll to Top