CVE-2026-19478
GitLab vulnerability analysis and mitigation

Overview

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. Under certain conditions, the flaw allows an unauthenticated remote attacker to modify or delete public projects and user data via a malicious GraphQL directive. It was disclosed and patched on August 17, 2026, with a CVSS v3.1 base score of 9.4 (Critical) (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), arising from insufficient validation of GraphQL directive inputs in GitLab's API layer (GitHub Advisory). An unauthenticated attacker can craft a malicious GraphQL directive and submit it over the network with no privileges or user interaction required, exploiting the flaw under certain unspecified conditions to manipulate or destroy public project data. The vulnerability was originally reported via HackerOne (report #3926431) and tracked internally at GitLab work item #611377 (GitHub Advisory). No public proof-of-concept exploit code has been confirmed at the time of disclosure.

Impact

Successful exploitation allows an unauthenticated attacker to remotely modify or delete public GitLab projects and associated user data, resulting in high integrity and availability impact. There is also a low confidentiality impact, potentially exposing limited project metadata or user information. The attack is automatable and network-accessible, meaning large-scale or targeted destruction of public repositories is feasible without any credentials (GitHub Advisory, The Hacker News).

Exploitability

As of disclosure on August 17, 2026, there is no confirmed public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is reported at 0.0, reflecting low current exploitation probability, though the vulnerability is marked as automatable by NVD SSVC analysis. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A GitHub repository (HORKimhab/CVE-2026-19650-CVE-2026-19478) referencing this CVE appeared shortly after disclosure, but no weaponized exploit has been confirmed.

Exploitation steps

  1. Reconnaissance: Identify internet-facing GitLab CE/EE instances running versions 18.2–18.11.10, 19.0.0–19.0.7, 19.1.0–19.1.5, or 19.2.0–19.2.3 using tools such as Shodan, Censys, or FOFA by querying for GitLab login pages or version banners.
  2. Identify target public projects: Browse the GitLab instance without authentication to enumerate publicly accessible projects and their identifiers via the web UI or GraphQL API (/api/graphql).
  3. Craft malicious GraphQL directive: Construct a GraphQL mutation or query containing a specially crafted directive that exploits the code injection flaw in GitLab's GraphQL processing layer, targeting project modification or deletion operations.
  4. Submit unauthenticated request: Send the crafted GraphQL request to the /api/graphql endpoint without any authentication headers, leveraging the missing authorization check under the specific triggering conditions.
  5. Achieve impact: If the conditions are met, the server processes the injected directive and executes unauthorized modification or deletion of the targeted public project data or user records (GitHub Advisory, The Hacker News).

Indicators of compromise

  • Network: Unusual unauthenticated POST requests to /api/graphql containing GraphQL directives with unexpected or malformed syntax; high-volume GraphQL mutation requests from a single IP targeting project deletion or modification operations.
  • Logs: GitLab application logs (production.log) showing GraphQL mutation errors or unexpected project deletion/modification events attributed to unauthenticated sessions; Rails exception logs referencing GraphQL directive processing.
  • Application Events: Sudden disappearance or modification of public projects with no corresponding authenticated user activity in audit logs; audit log entries showing project deletions with no associated user identity.
  • Process: Unexpected GitLab Sidekiq background jobs triggered for bulk project destruction without a corresponding admin or owner action.

Mitigation and workarounds

GitLab has released patched versions addressing this vulnerability: 18.11.11, 19.0.8, 19.1.6, and 19.2.4. All GitLab CE/EE administrators running affected versions (18.2–18.11.10, 19.0.x, 19.1.x, 19.2.x) should upgrade immediately (GitHub Advisory, GitLab Patch Release). If immediate patching is not possible, restrict network access to GitLab instances (e.g., via firewall rules or VPN), limit public project exposure, and monitor GraphQL API traffic for anomalous unauthenticated mutation requests.

Community reactions

The vulnerability received significant coverage from security media outlets including The Hacker News, which published an article titled "Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects" (The Hacker News). Security community members on Mastodon (infosec.exchange) and Reddit's r/SecOpsDaily discussed the severity and urged rapid patching. The FOFA threat intelligence bot also flagged the CVE on social media, indicating active interest from the reconnaissance community. Multiple security news aggregators (SecurityOnline, CyberPress, IT Security News) republished coverage, reflecting broad industry awareness of the critical rating.

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19478CRITICAL9.4
  • GitLab logoGitLab
  • gitlab-rails-19.1
NoYesAug 17, 2026
CVE-2026-19228HIGH8.5
  • GitLab logoGitLab
  • gitlab
NoYesAug 12, 2026
CVE-2026-19650HIGH7.1
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 17, 2026
CVE-2026-6821MEDIUM4.3
  • GitLab logoGitLab
  • gitlab
NoYesAug 12, 2026
CVE-2026-4879MEDIUM4.3
  • GitLab logoGitLab
  • gitlab
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management