H4x0r.DZ 🇰🇵[verified]@h4x0r_dzPatch
GitLab addressed CVE‑2026‑19478, a critical unauthenticated code‑injection flaw, with an official patch release.
watchTowr[verified]@watchtowrcyberPoC
watchTowr demonstrated a proof of concept for GitLab CVE‑2026‑19478, enabling unauthenticated modification or deletion of public projects; administrators should upgrade or restrict /api/graphql access immediately.
Nicolas Krassas[verified]@DinosnPoC
The post announces a public lab with a safe PoC for GitLab CVE‑2026‑19478 and CVE‑2026‑19650 and links to a GitHub repository, but it provides no exploit code, patches, technical specifications, or reports of active exploitation.
dbugs[verified]@ptdbugsPoC
A proof‑of‑concept exploit for CVE‑2026‑19478 is available, illustrating unauthenticated remote modification/deletion via GraphQL, while GitLab has released patches for the affected versions.
FOFA[verified]@fofabotDisclosure
The text announces a critical unauthenticated GraphQL vulnerability in GitLab, providing technical details and patch information, but no PoC, exploit code, or evidence of active exploitation.
Nicolas Krassas[verified]@DinosnPoC
The author reports reproducing GitLab CVE‑2026‑19478, holds back a lab release due to its destructive nature, and notes a 90‑day embargo on the PoC as too long.
ZoomEye[verified]@zoomeye_teamDisclosure
A critical vulnerability alert for CVE-2026-19478 affecting GitLab, linking to DarkEye for analysis and providing ZoomEye search parameters for target identification.
Abhishek[verified]@aacle_Exploit
The author reports on CVE‑2026‑19478, revealing an unauthenticated GraphQL query that can delete GitLab projects and provides a GitHub‑hosted PoC demonstrating the exploit.