Nicolas Krassas[verified]@DinosnPoC
The tweet announces a public, safe PoC lab for GitLab CVE-2026-19478 and CVE-2026-19650, providing a GitHub link but lacking detailed exploit code, patch info, or technical vulnerability specifics.
OX Security[verified]@OX__SecurityDisclosure
The tweet announces two GitLab GraphQL vulnerabilities with high severity scores, links to a detailed report, but does not mention any PoC, exploit code, active use, or patch information.
Checkmarx Zero[verified]@CheckmarxZeroPatch
GitLab released an out‑of‑band patch for CVE‑2026‑19478 (code‑injection, CVSS 9.4) and also addressed CVE‑2026‑19650 (CSRF, CVSS 7.1), with version guidance and a link to the full advisory.
Soy Nube Negra[verified]@Soy_Nube_NegraPatch
The tweet announces CVE-2026-19478, a high‑severity GraphQL weakness in self‑managed GitLab, and urges immediate patching or mitigation, providing version details and a clear workaround.
CyberSignal | Cybersecurity News[verified]@XQOPTRXDisclosure
GitLab discloses that it has patched the high‑severity CVE‑2026‑19478 (and CVE‑2026‑19650) and urges users to upgrade; no PoC or active exploitation is reported.
LinuxGeek 🐧@NewsOfLinuxPatch
The tweet highlights CVE‑2026‑19650, noting high integrity and availability impact, CSRF vulnerability in the GraphQL handler, and that a patch addresses the issue.
iototsecnews@iototsecnewsPatch
The article discloses a critical GitLab GraphQL flaw (CVE‑2026‑19478) that could let attackers alter or delete public projects, and urges users to apply the 19.2.4 patch immediately.
LinuxGeek 🐧@NewsOfLinuxPatch
The post announces a patch that addresses CVE-2026-19650, mentioning the vulnerability type (CSRF in GraphQL mutations) and the affected GitLab versions.