Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-19478 GitLab GraphQL unauthenticated project deletion

Summary

EQSTLab's PoC for CVE-2026-19478 (CVSS 9.4): GitLab's @gl_introduced fallback resolves arbitrary zero-arg methods — unauthenticated 'destroy' queries delete public projects; fixed in 18.11.11/19.2.4.

Why it matters

This vulnerability allows remote unauthenticated actors to delete projects in vulnerable GitLab instances, necessitating immediate patching.
Vendor
GitLab
Product
GitLab CE/EE
Affected versions
18.2–18.11.10, 19.0.0–19.0.7, 19.1.0–19.1.5, 19.2.0–19.2.3
CVSS
9.1
Published
Collected

original ↗

Related coverage

back