GitLab CVE-2026-19478 Is Under Active Exploitation
What happened
GitLab disclosed and patched CVE-2026-19478, a critical code-injection issue affecting GitLab CE and EE. Multiple reports indicate exploit activity started quickly after disclosure, reducing defender response time.
Who is affected
Organizations running internet-facing self-managed GitLab instances in affected release lines are at highest risk, especially where public project access is enabled.
Why it matters
The flaw can impact software integrity and trust in development workflows. Attackers may tamper with public repositories or project data, creating downstream risk for engineering, release, and security teams.
Technical details
- CVE: CVE-2026-19478
- Severity: CVSS 9.4 (critical)
- Exploitation status: Reported as actively exploited
- Affected versions:
- 18.2 before 18.11.11
- 19.0 before 19.0.8
- 19.1 before 19.1.6
- 19.2 before 19.2.4
- Fixed versions:
- 18.11.11
- 19.0.8
- 19.1.6
- 19.2.4
- Reported attack path references GraphQL abuse in vulnerable configurations.
Recommended actions
- Patch immediately to a fixed GitLab version.
- Prioritize internet-facing and public-facing instances.
- Review web and reverse-proxy logs for suspicious GraphQL requests, including probes referencing unusual directives.
- If patching is delayed, restrict unauthenticated access to /api/graphql and limit public repository exposure.
- Validate repository integrity and maintainers permissions after patching.
Sources
- https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html
- https://about.gitlab.com/releases/
