GitLab patches critical CVE-2026-19478 (CVSS 9.4): unauthenticated attackers can modify or delete projects via GraphQL injection. Affects self-managed versions https:// deafnews.it/en/article/gitlabs

4): unauthenticated attackers can modify or delete projects via GraphQL injection.

2 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

GitLab patches critical CVE-2026-19478 (CVSS 9.4): unauthenticated attackers can modify or delete projects via GraphQL injection. Affects self-managed versions https:// deafnews.it/en/article/gitlabs

mastodon:infosec-exchangeother38d ago kagi ↗

GitLab patches critical CVE-2026-19478 (CVSS 9.4): unauthenticated attackers can modify or delete projects via GraphQL injection. Affects self-managed versions https:// deafnews.it/en/article/gitlabs -future-field-security-feature-turns-weapon-emergency-patches-for-cve-2026-19478