CVE-2026-19478
Improper Control of Generation of Code ('Code Injection') in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
Coverage 2 sources
-
2026-08-18
Help Net Security
critical
Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
GitLab patches critical code injection flaw allowing attackers to modify or delete public projects.
-
2026-08-19
GovInfoSecurity
critical
GitLab Code Injection Flaw Exploited in the Wild
CVE-2026-19478, a GitLab code injection flaw, is being exploited in the wild, allowing unauthenticated attackers to alter public projects.
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands