Back Korben.Info GitLab - the flaw that forced them to reopen a dead branch
GitLab released yesterday (Monday, August 17th) an emergency patch , completely outside its usual schedule, for a vulnerability that allows someone with no account and no password to modify or delete your public projects and user data. Yeah, it's pretty bad - which is exactly why its CVSS score is 9.4 out of 10.
Five days earlier, on August 12th, GitLab had published its routine patch for versions 19.2, 19.1 and 19.0. That's a normal scope since its maintenance policy only covers the stable release and the two ones. But because this is an exceptional situation, the August 17th patch covers a fourth version - 18.11 - whose support had ended on July 16th. They actually went back and reopened a dead branch just to patch this MASSIVE issue!
As for the vulnerability itself, we know almost nothing it. Tagged CVE-2026-19478, it involves a GraphQL directive, but GitLab won't say which one, or under what conditions it triggers. The technical details will come out around mid-November - 90 days after the patch, as usual - to make sure everyone has had time to patch their install.
Now, the good news is that if you're on GitLab.com or its Dedicated version, you don't need to do anything, since it's already patched. This whole thing only affects self-hosted instances.
And among those, not everyone is equally at risk. The attack vector goes through the network and targets public projects. That means your instance tucked behind a VPN with no public visibility is at much less risk than one exposing its repositories to the internet.
As for updating, it depends on where you're starting from. Between versions 18.2 and 18.10, no patch exists for your branch. You'll need to upgrade all the way to 18.11.11, stopping at the 18.5 and 18.8 milestones if they're along the way.
If you're already on 18.11, grab 18.11.11. On a 19.x, it's 19.0.8, 19.1.6 or 19.2.4. And if you're older than 18.2? Well, GitLab doesn't list those versions as affected, but they haven't received any patches in quite a while, so you should really update anyway, you know...
For now, no attacks have been reported and no exploit or PoC has surfaced on GitHub. That doesn't mean much, I'll grant you that - but we take comfort where we can...
Source: The Hacker News
No paywall or programmatic ads. If the site is useful to you and you want it to remain free and independent, you can support it on Patreon.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
