Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
9.4
CVE-2026-19478PATCHED
gitlab · gitlab

Improper Control of Generation of Code ('Code Injection') in GitLab

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Affected Products

VendorProductVersions
gitlabgitlab18.2, 19.0, 19.1, 19.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcegitlabcert_advisory90%

References

  • https://gitlab.com/gitlab-org/gitlab/-/work_items/611377
  • https://hackerone.com/reports/3926431(technical-description, exploit, permissions-required)
  • https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-19478.yaml(exploit, nuclei)

Related News (13 articles)

Tier D
Help Net Security23h ago
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
→ No new info (linked only)
Tier D
The Hacker News3d ago
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
→ No new info (linked only)
Tier D
Heise Security3d ago
Angriffsversuche auf GitLab-Lücke beobachtet
→ No new info (linked only)
Tier D
SecurityWeek3d ago
Critical GitLab Flaw Exploited Shortly After Disclosure
→ No new info (linked only)
Tier D
Dark Reading5d ago
Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
→ No new info (linked only)
Tier D
CSO Online5d ago
Critical GitLab flaw allows attackers to delete and modify public repos
→ No new info (linked only)
Tier D
Help Net Security5d ago
Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
→ No new info (linked only)
Tier B
BSI Advisories5d ago
[NEU] [hoch] GitLab: Mehrere Schwachstellen ermöglichen Manipulation von Dateien
→ No new info (linked only)
Tier D
SecurityWeek5d ago
GitLab Patches Critical Code Injection Vulnerability
→ No new info (linked only)
Tier D
Heise Security5d ago
Kritische Sicherheitslücke in GitLab: Angreifer können Projekte löschen
→ No new info (linked only)
Tier B
CERT-FR6d ago
Multiples vulnérabilités dans GitLab (18 août 2026)
→ No new info (linked only)
Tier D
The Hacker News6d ago
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
→ No new info (linked only)
Tier C
VulDB6d ago
CVE-2026-19478 | GitLab up to 18.11.10/19.0.7/19.1.5/19.2.3 GraphQL Directive authorization
→ No new info (linked only)
CVSS 3.19.4 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
18.11.1119.0.819.1.619.2.4
CWECWE-94
PublishedAug 17, 2026
Trending Score71
Source articles13
Independent9
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-19650
Cross-Site Request Forgery (CSRF) in GitLab
Trending: 34
HIGHCVE-2026-10053
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
Trending: 25
HIGHCVE-2026-15216
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Trending: 14
HIGHCVE-2026-15217
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Trending: 14
HIGHCVE-2026-16627
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Trending: 14

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 17, 2026
Discovered by ZDM
Aug 17, 2026
Exploit Available
Aug 17, 2026
Patch Available
Aug 17, 2026