- Sources: GitLab critical patch release 19.2.4, 19.1.6, 19.0.8, 18.11.11, CVE-2026-19478, CVE-2026-19650, HN discussion
- Summary: GitLab released 19.2.4, 19.1.6, 19.0.8, and 18.11.11 on 2026-08-17 as an ad-hoc critical patch outside the scheduled release cycle. CVE-2026-19478 is rated CVSS 9.4 and GitLab describes it as allowing an unauthenticated user to remotely modify or delete public projects and user data through a GraphQL directive, affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The same release carries CVE-2026-19650, a GraphQL multiplex cross-site request forgery rated CVSS 7.1.
- Why it matters: Every self-managed GitLab instance on an affected version can be modified by an unauthenticated remote user until an operator upgrades it, and the fix requires operator action rather than arriving server side.
- Follow-up: Track whether exploitation of CVE-2026-19478 is reported in the wild.
send feedback on this story