Summary
GitLab issued an emergency security update to fix a critical GraphQL code injection vulnerability (CVE-2026-19478) that allows unauthenticated attackers to remotely delete or modify public projects and user data.
Take Action:
If you run a self-managed GitLab server (version 18.2 through 19.2.3), update it ASAP to 19.2.4, 19.1.6, 19.0.8, or 18.11.11. The patch is quick and won't take your system offline. Before you patch, check your logs for unusual GraphQL activity so you know nobody has already deleted or altered your projects or user data.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)