CVE detail
CVE-2026-19478
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 9
- within the 30d window
- Peak daily
- 4
- highest bucket
Evidence
Source links by recency
9 source links · newest first
Linked URL: https://techupdate24.com/gitlab-cve-2026-19478-graphql-flaw/ | Posted by sysadmin_diarie | 1 points | 0 comments
communitynews.ycombinator.comAug 19, 2026, 7:29 AMl details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478.
newswww.darkreading.comAug 18, 2026, 9:25 PMreleases also address a second high-risk cross-site request forgery (CSRF) flaw. The critical vulnerability, tracked as CVE-2026-19478 , is described as a code injection issue through the GraphQL directive and was reported privately to GitLab through its bug bounty program on HackerOne. However, even if the flaw’s details are not yet public, researcher
newswww.csoonline.comAug 18, 2026, 7:33 PM- Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)Help Net Security
installations be upgraded … More → The post Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) appeared first on Help Net Security .
newswww.helpnetsecurity.comAug 18, 2026, 11:38 AM - GitLab Patches Critical Unauthenticated GraphQL VulnerabilitySecurity Affairs
projects on self-managed servers. GitLab pushed out an emergency patch this week to address a critical flaw, tracked as CVE-2026-19478 (CVSS score of 9.4), that could let an attacker with zero credentials remotely modify or delete public projects and user […]
newssecurityaffairs.comAug 18, 2026, 8:44 AM - Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public ProjectsThe Hacker News
ould allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on
newsthehackernews.comAug 17, 2026, 9:03 PM - https://hackerone.com/reports/3926431hackerone.com
No excerpt available.
Exploithackerone.comAug 17, 2026, 8:16 PM No excerpt available.
Exploitgitlab.comAug 17, 2026, 8:16 PMNo excerpt available.
Vendor Advisorydocs.gitlab.comAug 17, 2026, 8:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-75911CVSS 8.5 · High
CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command…
- CVE-2026-75858CVSS 8.5 · High
CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement(…
- CVE-2026-73073CVSS 7.1 · High
Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficie…
- CVE-2026-45117CVSS 9.8 · Critical
MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to the con…
- CVE-2026-73343CVSS 10.0 · Critical
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
- CVE-2026-50187CVSS 8.8 · High
Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to sour…