Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
7.1
CVE-2026-19650PATCHED
gitlab · gitlab

Cross-Site Request Forgery (CSRF) in GitLab

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.

Affected Products

VendorProductVersions
gitlabgitlab18.2, 19.0, 19.1, 19.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcegitlabcert_advisory90%

References

  • https://gitlab.com/gitlab-org/gitlab/-/work_items/612617
  • https://hackerone.com/reports/3903669(technical-description, exploit, permissions-required)
  • https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/

Related News (7 articles)

Tier D
Heise Security3d ago
Angriffsversuche auf GitLab-Lücke beobachtet
→ No new info (linked only)
Tier E
Hacker News5d ago
GitLab CVE-2026-19478: GraphQL authorization bypass
→ No new info (linked only)
Tier D
CSO Online5d ago
Critical GitLab flaw allows attackers to delete and modify public repos
→ No new info (linked only)
Tier B
BSI Advisories5d ago
[NEU] [hoch] GitLab: Mehrere Schwachstellen ermöglichen Manipulation von Dateien
→ No new info (linked only)
Tier D
Heise Security6d ago
Kritische Sicherheitslücke in GitLab: Angreifer können Projekte löschen
→ No new info (linked only)
Tier B
CERT-FR6d ago
Multiples vulnérabilités dans GitLab (18 août 2026)
→ No new info (linked only)
Tier C
VulDB6d ago
CVE-2026-19650 | GitLab up to 18.11.10/19.0.7/19.1.5/19.2.3 GraphQL Query privileges management
→ No new info (linked only)
CVSS 3.17.1 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
18.11.1119.0.819.1.619.2.4
CWECWE-352
PublishedAug 17, 2026
Trending Score34
Source articles7
Independent6
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-19478
Improper Control of Generation of Code ('Code Injection') in GitLab
Trending: 70
HIGHCVE-2026-10053
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
Trending: 25
HIGHCVE-2026-15216
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Trending: 13
MEDIUMCVE-2026-4879
Missing Authorization in GitLab
Trending: 13
HIGHCVE-2026-15217
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Trending: 13

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 17, 2026
Discovered by ZDM
Aug 17, 2026
Patch Available
Aug 17, 2026