
GitLab Releases Critical Security Updates for GraphQL API Vulnerability (CVE-2026-19478)
CybersecurityVulnerabilitiesSoftwareSecurityDataIntegrity
GitLab released security updates to address a critical vulnerability (CVE-2026-19478) affecting its Community Edition (CE) and Enterprise Edition (EE) software. The flaw, rated with a CVSS score of 9.4, could allow unauthenticated attackers to remotely modify or delete public projects and user data under specific conditions. The vulnerability impacts GitLab’s GraphQL API, though no exact release date for the patches was specified in the notice. No additional technical details about exploitation methods or affected versions were provided. The issue was classified as Critical by GitLab.