Junglewise Threat Intelligence

CVE-2026-19478: GitLab CE/EE code injection via GraphQL directive

CVE-2026-19478 · Severity: critical · CVSS 9.4 · Published 2026-08-17

Technologies: GitLab Community Edition, GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab Community Edition and Enterprise Edition contain a critical vulnerability that allows unauthenticated attackers to modify or delete public projects and user data through a flaw in GraphQL directive handling. This affects self-managed GitLab instances and could lead to data loss, unauthorized changes to repositories, and reputational damage. Immediate patching is required for all affected versions.

Technical details

The vulnerability is a code injection issue in GraphQL directive processing that allows unauthenticated remote attackers to execute arbitrary operations. The flaw permits modification or deletion of public projects and user data without authentication or user interaction required. Attack vector is network-based with no preconditions (PR:N, UI:N). Affected versions include GitLab CE/EE 18.2–18.11.10, 19.0–19.0.7, 19.1–19.1.5, and 19.2–19.2.3. Patches are available in GitLab 18.11.11, 19.0.8, 19.1.6, and 19.2.4; immediate upgrade is strongly recommended.

Affected products

  • GitLab GitLab Community Edition 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, 19.2 before 19.2.4
  • GitLab GitLab Enterprise Edition 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, 19.2 before 19.2.4

Timeline

  • 2026-08-17: disclosed: Vulnerability disclosed and patched versions released
  • 2026-08-17: patched: Patched versions released: 18.11.11, 19.0.8, 19.1.6, 19.2.4

References

Related threats