DEV Community

Cover image for GitLab Issues Emergency Patch for Critical GraphQL Flaw Allowing Remote Project Deletion
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

GitLab Issues Emergency Patch for Critical GraphQL Flaw Allowing Remote Project Deletion

Summary

GitLab issued an emergency security update to fix a critical GraphQL code injection vulnerability (CVE-2026-19478) that allows unauthenticated attackers to remotely delete or modify public projects and user data.

Take Action:

If you run a self-managed GitLab server (version 18.2 through 19.2.3), update it ASAP to 19.2.4, 19.1.6, 19.0.8, or 18.11.11. The patch is quick and won't take your system offline. Before you patch, check your logs for unusual GraphQL activity so you know nobody has already deleted or altered your projects or user data.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)