
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. Under certain conditions, the flaw allows an unauthenticated remote attacker to modify or delete public projects and user data via a malicious GraphQL directive. It was disclosed and patched on August 17, 2026, with a CVSS v3.1 base score of 9.4 (Critical) (GitHub Advisory).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), arising from insufficient validation of GraphQL directive inputs in GitLab's API layer (GitHub Advisory). An unauthenticated attacker can craft a malicious GraphQL directive and submit it over the network with no privileges or user interaction required, exploiting the flaw under certain unspecified conditions to manipulate or destroy public project data. The vulnerability was originally reported via HackerOne (report #3926431) and tracked internally at GitLab work item #611377 (GitHub Advisory). No public proof-of-concept exploit code has been confirmed at the time of disclosure.
Successful exploitation allows an unauthenticated attacker to remotely modify or delete public GitLab projects and associated user data, resulting in high integrity and availability impact. There is also a low confidentiality impact, potentially exposing limited project metadata or user information. The attack is automatable and network-accessible, meaning large-scale or targeted destruction of public repositories is feasible without any credentials (GitHub Advisory, The Hacker News).
As of disclosure on August 17, 2026, there is no confirmed public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is reported at 0.0, reflecting low current exploitation probability, though the vulnerability is marked as automatable by NVD SSVC analysis. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A GitHub repository (HORKimhab/CVE-2026-19650-CVE-2026-19478) referencing this CVE appeared shortly after disclosure, but no weaponized exploit has been confirmed.
/api/graphql)./api/graphql endpoint without any authentication headers, leveraging the missing authorization check under the specific triggering conditions./api/graphql containing GraphQL directives with unexpected or malformed syntax; high-volume GraphQL mutation requests from a single IP targeting project deletion or modification operations.production.log) showing GraphQL mutation errors or unexpected project deletion/modification events attributed to unauthenticated sessions; Rails exception logs referencing GraphQL directive processing.GitLab has released patched versions addressing this vulnerability: 18.11.11, 19.0.8, 19.1.6, and 19.2.4. All GitLab CE/EE administrators running affected versions (18.2–18.11.10, 19.0.x, 19.1.x, 19.2.x) should upgrade immediately (GitHub Advisory, GitLab Patch Release). If immediate patching is not possible, restrict network access to GitLab instances (e.g., via firewall rules or VPN), limit public project exposure, and monitor GraphQL API traffic for anomalous unauthenticated mutation requests.
The vulnerability received significant coverage from security media outlets including The Hacker News, which published an article titled "Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects" (The Hacker News). Security community members on Mastodon (infosec.exchange) and Reddit's r/SecOpsDaily discussed the severity and urged rapid patching. The FOFA threat intelligence bot also flagged the CVE on social media, indicating active interest from the reconnaissance community. Multiple security news aggregators (SecurityOnline, CyberPress, IT Security News) republished coverage, reflecting broad industry awareness of the critical rating.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."