Skip to main content
Back to Newswire
Security BREAKING

GitLab patches critical unauthenticated GraphQL project-deletion flaw

GitLab patches critical unauthenticated GraphQL project-deletion flaw Image: Primary
GitLab released updates for a critical GraphQL vulnerability that could, under certain conditions, let an unauthenticated attacker remotely modify or delete public projects and user data on self-managed installations. GitLab rated CVE-2026-19478 at CVSS 9.4 and issued fixes in versions 19.2.4, 19.1.6, 19.0.8 and 18.11.11. GitLab.com and GitLab Dedicated were already patched. The advisory does not name the affected directive or disclose the conditions required for exploitation.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire