Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Security Flaw in GitLab Resolved

Critical Security Flaw in GitLab Resolved

Posted on August 18, 2026 By CWS

GitLab has issued crucial updates addressing two significant vulnerabilities, including a severe code injection risk that could be exploited without user authentication. The security issue, identified as CVE-2026-19478 and carrying a CVSS score of 9.4, permits unauthorized modifications or deletions of user data and public projects via a GraphQL directive, according to GitLab’s advisory.

Details of the Vulnerabilities

The critical vulnerability CVE-2026-19478 allows attackers to manipulate user data without authentication, posing a substantial threat to data integrity. Another security flaw, CVE-2026-19650, which has a CVSS score of 7.1, involves a cross-site request forgery (CSRF) issue affecting the GraphQL multiplex query handler. This flaw could have enabled unauthorized execution of mutations via GET requests due to insufficient request validation.

Affected Versions and Patches

All versions of GitLab Community Edition (CE) and Enterprise Edition (EE) from 18.2, 19.0, 19.1, and 19.2 onwards are susceptible to these vulnerabilities. GitLab has addressed these issues in the latest updates: versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4. Users of self-managed installations are urged to update to these versions promptly to mitigate potential risks.

Automatic Updates and Security Reporting

The patches have been automatically deployed to GitLab.com and GitLab Dedicated, requiring no further action from their users. Both security issues were reported through GitLab’s HackerOne bug bounty program, underlining the importance of community-driven security efforts. There are currently no reports of these vulnerabilities being actively exploited in the wild.

These updates emphasize the need for timely software maintenance to safeguard against emerging threats. For users and organizations relying on GitLab for code management and collaboration, staying updated with the latest security patches is crucial to maintaining data security and system integrity.

Security Week News Tags:code injection, code management, CSRF, Cybersecurity, data protection, GitLab, GitLab CE, GitLab EE, GraphQL, HackerOne, Patch, Security, software update, Update, Vulnerability

Post navigation

Previous Post: New PATCHCORD Backdoor Threatens Afghan and Indian Sectors
Next Post: WordPress Plugin Flaw Risks 600,000 Sites with Attacks

Related Posts

Anthropic Alerts Users to Malware Threats on Claude Accounts Anthropic Alerts Users to Malware Threats on Claude Accounts Security Week News
AI Impacts Cybersecurity: Key Developments Unveiled AI Impacts Cybersecurity: Key Developments Unveiled Security Week News
Going Into the Deep End: Social Engineering and the AI Flood Going Into the Deep End: Social Engineering and the AI Flood Security Week News
Origin Energy Data Breach Impacts 900,000 Customers Origin Energy Data Breach Impacts 900,000 Customers Security Week News
AI Governance: A Leadership Essential for Modern Businesses AI Governance: A Leadership Essential for Modern Businesses Security Week News
Monnai Raises  Million for Identity and Risk Data Infrastructure Monnai Raises $12 Million for Identity and Risk Data Infrastructure Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Software Updates for Credential Theft
  • Major Cybersecurity Breaches and AI Threats Uncovered
  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address
  • Fake Zoom Installer on macOS Spreads CloudSyncD Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Software Updates for Credential Theft
  • Major Cybersecurity Breaches and AI Threats Uncovered
  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address
  • Fake Zoom Installer on macOS Spreads CloudSyncD Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark