Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4305 articles · 196683 vulns · 37/41 feeds (7d)
← Back to list
9.4
CVE-2026-19478PATCHED
gitlab · gitlab

Improper Control of Generation of Code ('Code Injection') in GitLab

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Affected Products

VendorProductVersions
gitlabgitlab18.2, 19.0, 19.1, 19.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcegitlabcert_advisory90%

References

  • https://gitlab.com/gitlab-org/gitlab/-/work_items/611377
  • https://hackerone.com/reports/3926431(technical-description, exploit, permissions-required)
  • https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-19478.yaml(exploit, nuclei)

Related News (15 articles)

Tier D
The Hacker News9h ago
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
→ No new info (linked only)
Tier B
CERT-FR1d ago
Bulletin d'actualité CERTFR-2026-ACT-036 (24 août 2026)
→ No new info (linked only)
Tier D
Help Net Security1d ago
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
→ No new info (linked only)
Tier D
The Hacker News3d ago
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
→ No new info (linked only)
Tier D
Heise Security4d ago
Angriffsversuche auf GitLab-Lücke beobachtet
→ No new info (linked only)
Tier D
SecurityWeek4d ago
Critical GitLab Flaw Exploited Shortly After Disclosure
→ No new info (linked only)
Tier D
Dark Reading6d ago
Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
→ No new info (linked only)
Tier D
CSO Online6d ago
Critical GitLab flaw allows attackers to delete and modify public repos
→ No new info (linked only)
Tier D
Help Net Security6d ago
Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
→ No new info (linked only)
Tier B
BSI Advisories6d ago
[NEU] [hoch] GitLab: Mehrere Schwachstellen ermöglichen Manipulation von Dateien
→ No new info (linked only)
Tier D
SecurityWeek6d ago
GitLab Patches Critical Code Injection Vulnerability
→ No new info (linked only)
Tier D
Heise Security6d ago
Kritische Sicherheitslücke in GitLab: Angreifer können Projekte löschen
→ No new info (linked only)
Tier B
CERT-FR7d ago
Multiples vulnérabilités dans GitLab (18 août 2026)
→ No new info (linked only)
Tier D
The Hacker News7d ago
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
→ No new info (linked only)
Tier C
VulDB7d ago
CVE-2026-19478 | GitLab up to 18.11.10/19.0.7/19.1.5/19.2.3 GraphQL Directive authorization
→ No new info (linked only)
CVSS 3.19.4 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
18.11.1119.0.819.1.619.2.4
CWECWE-94
PublishedAug 17, 2026
Trending Score75
Source articles15
Independent9
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-19650
Cross-Site Request Forgery (CSRF) in GitLab
Trending: 32
HIGHCVE-2026-10053
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
Trending: 28
HIGHCVE-2026-15216
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Trending: 13
HIGHCVE-2026-15217
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Trending: 13
HIGHCVE-2026-16627
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Trending: 13

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 17, 2026
Discovered by ZDM
Aug 17, 2026
Exploit Available
Aug 17, 2026
Patch Available
Aug 17, 2026