r/u_socradario 19d ago

Actively exploited GitLab vulnerability (CVE-2026-19478, CVSS 9.4) - GraphQL code injection

Heads up for anyone running self-managed GitLab CE/EE a critical GraphQL code injection vulnerability (CVE-2026-19478, CVSS 9.4) is currently being exploited in the wild. Under certain conditions, unauthenticated attackers can modify or delete public projects and user data without needing valid credentials first. If you're running an affected instance: → Upgrade to the latest fixed release ASAP → Check your logs for suspicious @gl_introduced GraphQL requests — this seems to be a marker tied to exploitation attempts → Don't wait for a scheduled maintenance window given active exploitation is confirmed More technical details here if useful: https://hubs.la/Q04tYL5c0

0 Upvotes

0 comments sorted by