Skip to content

OSG-SEC-2026-08-21 Critical-GitLab Vulnerability-CVE-2026-19478

Dear OSG Security Contacts,

A critical vulnerability affecting self-managed GitLab Community Edition (CE) and Enterprise Edition (EE), CVE-2026-19478, has been publicly disclosed [1] [2]. Exploitation attempts have reportedly been observed in the wild [3].

WHAT ARE THE VULNERABILITIES:

CVE-2026-19478 is a code-injection vulnerability in GitLab’s GraphQL interface. Under certain conditions, a remote, unauthenticated attacker can use a malicious GraphQL directive to modify or delete publicly accessible projects and associated user data. Security researchers have reported observing exploitation attempts [3].

IMPACTED VERSIONS:

The following GitLab CE and EE releases are affected:

GitLab 18.2 through versions earlier than 18.11.11;  
GitLab 19.0 through versions earlier than 19.0.8;  
GitLab 19.1 through versions earlier than 19.1.6; and. 
GitLab 19.2 through versions earlier than 19.2.4.

MITIGATION

GitLab has not published a vendor-supported workaround or mitigation.

WHAT YOU SHOULD DO:

Identify any self-managed GitLab CE or EE instances and determine their installed versions. GitLab.com and GitLab Dedicated are already running the patched version. Immediately upgrade affected installations to a fixed release or a later supported version:

GitLab 18.11.11 or later;  
GitLab 19.0.8 or later;  
GitLab 19.1.6 or later; or. 
GitLab 19.2.4 or later.

If you cannot immediately upgrade it is recommended that you block access to your GitLab service until it can be upgraded. Because exploitation attempts have reportedly been observed in the wild [3], review GitLab, reverse-proxy, WAF, and other web-access logs for suspicious unauthenticated GraphQL requests. Third-party researchers recommend searching for requests containing: @gl_introduced.

REFERENCES

[1] https://www.cve.org/CVERecord?id=CVE-2026-19478
[2] https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/
[3] https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html