Back Heise.De Critical security vulnerability in GitLab: Attackers can delete projects
The code-hosting platform GitLab is vulnerable. Attackers can exploit two security vulnerabilities to manipulate or even delete project data.
In a warning message, the developers assure that they have fixed versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4 of the GitLab Community Edition and Enterprise Edition. Admins of on-premises installations should act promptly and install one of the current versions. According to the developers, the fixed versions are already installed on GitLab.com.
If attackers exploit a “ critical ” security vulnerability (CVE-2026-19478), they can alter or delete public projects and user data. The vulnerability is found in the GraphQL API of a GitLab instance. If an attacker can access it, they exploit the flaw with prepared GraphQL requests.
In the second case (CVE-2026-19650 “ high ”), a victim must cooperate, for example, by clicking on a manipulated link. Subsequently, an attacker can exploit the GraphQL API via GET requests and, for example, change project settings. If a victim has admin rights, an attacker could compromise entire instances with these rights.
So far, the software developer has no indications that attackers are already exploiting the vulnerabilities. However, they strongly advise a swift update. Accordingly, admins should install the patches soon to protect their instances from possible attacks. After all, attackers can cause considerable damage in software development environments. Anyone using a version no longer supported must upgrade to one that is still supported.
Most recently, the GitLab developers advised a swift update at the end of July.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
