Skip to content
Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

Feeds2.Feedburner Sinisa Markovic August 18, 2026

GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.11.11. “These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded … More →