CVE-2026-19650Patch(gitlab / gitlab)

LOWCVSS 7.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch gitlab gitlab systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 7 signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 4 mentions (2026-08-18); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-08-18: 4Mentions · 2026-08-19: 1Mentions · 2026-08-23: 1Mentions · 2026-08-25: 1Mentions · 2026-08-30: 1PoC Mentioned / Linked · 2026-08-23: 1Patch / Workaround · 2026-08-18: 3Patch / Workaround · 2026-08-19: 1Patch / Workaround · 2026-08-25: 1Patch / Workaround · 2026-08-30: 1Technical Details · 2026-08-18: 4Technical Details · 2026-08-19: 1Technical Details · 2026-08-25: 1Technical Details · 2026-08-30: 108-1808-1908-2308-2508-30
Signal classification3 categories
Patch
562.5%
Disclosure
225.0%
PoC
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-08-184
Disclosure1Patch3
2026-08-191
Disclosure1
2026-08-231
PoC1
2026-08-251
Patch1
2026-08-301
Patch1
Full discourse8 posts
  • Nicolas Krassas@Dinosn
    PoC

    Opening public the lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced ) , since it's already around. This is a 'safe env setup' https://github.com/dinosn/gitlab-cve-2026-19478-lab

    Post summary

    The tweet announces a public, safe PoC lab for GitLab CVE-2026-19478 and CVE-2026-19650, providing a GitHub link but lacking detailed exploit code, patch info, or technical vulnerability specifics.

    215070366.6K
    161.9K followersView on X
  • OX Security@OX__Security
    Disclosure

    🚨 One GraphQL Directive. Two GitLab CVEs. CVE-2026-19478 (9.4): unauthenticated users can modify/delete public projects + user data CVE-2026-19650 (7.1): CSRF can execute mutations using a logged-in user’s session FULL REPORT: https://www.ox.security/blog/gitlab-graphql-cve-2026-19478-19650/ -- #CyberSecurity #CVE https://t.co/6jLZUZkdJo

    Post summary

    The tweet announces two GitLab GraphQL vulnerabilities with high severity scores, links to a detailed report, but does not mention any PoC, exploit code, active use, or patch information.

    02080450
    403 followersView on X
  • Checkmarx Zero@CheckmarxZero
    Patch

    Emergency patch time if you're managing your own #GitLab instance! Out of band patch was released for CVE-2026-19478 (CVSS=9.4), a code-injection vulnerability in GraphQL directive handling that can be exploited without authentication. The patch also covers a less-severe CVE-2026-19650 (CVSS=7.1) CSRF issue, but since it requires user interaction, it's a pretty normal "eval against your risk tolerance" type thing. Patch up to 19.2.4, 19.1.6, 19.0.8, or 18.11.11 -- if you're on http://GitLab.com, that's already done for you. Patches don't cover 18.2–18.10; those branches need to move to 8.11.11 or a 19.x line. Full advisory: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/ #AppSec #VulnerabilityManagement #DevSecOps #SupplyChainSecurity

    Post summary

    GitLab released an out‑of‑band patch for CVE‑2026‑19478 (code‑injection, CVSS 9.4) and also addressed CVE‑2026‑19650 (CSRF, CVSS 7.1), with version guidance and a link to the full advisory.

    00010108
    242 followersView on X
  • LinuxGeek 🐧@NewsOfLinux
    Patch

    @MadeItHappenX Worth taking into that meeting: the vector is C:L/I:H/A:H. Integrity and availability rated high, confidentiality only low. The exposure is destruction and tampering. Same patch also carries CVE-2026-19650, CSRF in the GraphQL multiplex handler, mutations via GET.

    Post summary

    The tweet highlights CVE‑2026‑19650, noting high integrity and availability impact, CSRF vulnerability in the GraphQL handler, and that a patch addresses the issue.

    0001035
    121 followersView on X
  • Soy Nube Negra@Soy_Nube_Negra
    Patch

    [GITLAB] — CVE-2026-19478: un atacante sin cuenta puede borrar o modificar proyectos públicos. Impacto: instancias self-managed de GitLab CE/EE (ramas 18.2 a 19.2) permiten a un atacante no autenticado alcanzar mutaciones GraphQL que borran o cambian proyectos públicos y datos de usuario. http://GitLab.com y Dedicated ya están parcheados; el riesgo es el self-managed expuesto. Estado: CVSS 9.4; parche de emergencia el 17 de agosto (19.2.4, 19.1.6, 19.0.8, 18.11.11). Acompañado de CVE-2026-19650 (CSRF en GraphQL). Acción hoy: 1. Actualiza a la versión fija ahora, no en la ventana programada. 2. Si no puedes, bloquea POST anónimos a /api/graphql con un WAF o proxy. 3. Revisa el log de auditoría por borrados/modificaciones sin autor. Cuándo fue la última vez que auditaste quién puede tocar tus proyectos públicos? Sigue a @Soy_Nube_Negra si te sirve este tipo de análisis. #GitLab #DevSecOps https://cybersecuritynews.com/gitlab-graphql-vulnerability/

    Post summary

    The tweet announces CVE-2026-19478, a high‑severity GraphQL weakness in self‑managed GitLab, and urges immediate patching or mitigation, providing version details and a clear workaround.

    0000051
    1.9K followersView on X
  • iototsecnews@iototsecnews
    Patch

    GitLab GraphQL の脆弱性 CVE-2026-19478 が FIX:公開プロジェクトの変更/削除が可能 https://iototsecnews.jp/2026/08/17/critical-gitlab-graphql-flaw-could-let-unauthenticated-attackers-delete-public-projects/ 開発支援ツールである GitLab CE/EE の緊急アップデート情報を解説する投稿です。通常スケジュール外で速報が提供された背景にあるのは、内部機能である GraphQL の検証処理における欠陥の深刻さです。該当箇所には CVE-2026-19478/CVE-2026-19650 の脆弱性が含まれており、悪用された場合には外部の第三者による公開プロジェクトやデータの変更/削除、ならびに不正なリクエスト実行といった被害が生じる恐れがあります。自身で運用サーバーを管理している場合は、公開済みの安全な修正版 (19.2.4 など) への速やかなアップデート作業が求められます。 #CVE202619478 #GitLab #GraphQL #Vulnerability

    Post summary

    The article discloses a critical GitLab GraphQL flaw (CVE‑2026‑19478) that could let attackers alter or delete public projects, and urges users to apply the 19.2.4 patch immediately.

    00000127
    510 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    CyberSignal Daily ✓ · 🛠️ DevSecOps · August 19, 2026 🎯 A CVSS 9.4 vulnerability involving one of the world's major development platforms. GitLab has patched CVE-2026-19478, a critical vulnerability rated CVSS 9.4. GitLab says that under certain conditions an unauthenticated remote user could modify or delete public projects and user data. GitLab strongly recommends that affected installations move to patched releases. A second GraphQL-related vulnerability, CVE-2026-19650, was rated 7.1 and fixed in the same security release. 🔗 Sources: GitLab Security / NVD / August 19 security coverage #GitLab #CVE #DevSecOps #Vulnerability #AppSec #CyberSecurity

    Post summary

    GitLab discloses that it has patched the high‑severity CVE‑2026‑19478 (and CVE‑2026‑19650) and urges users to upgrade; no PoC or active exploitation is reported.

    0000039
    82 followersView on X
  • LinuxGeek 🐧@NewsOfLinux
    Patch

    Same patch carries CVE-2026-19650, CSRF in the GraphQL multiplex handler, 7.1: mutations via GET requests. Affected range is 18.2 through 18.11.10, 19.0.0-19.0.7, 19.1.0-19.1.5, 19.2.0-19.2.3. Hosted https://gitlab.com and Dedicated already have it. https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/

    Post summary

    The post announces a patch that addresses CVE-2026-19650, mentioning the vulnerability type (CSRF in GraphQL mutations) and the affected GitLab versions.

    0000031
    121 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---

Explore more