ADVERTISEMENT

Critical GitLab flaw lets hackers delete or rewrite repositories – patch now

GitLab warns the 9.4-rated code injection vulnerability requires no user interaction to exploit.

GitLab

Image by jackpress | Shutterstock

Stefanie Schappert
Stefanie Schappert Senior Journalist
August 18, 2026 Updated: 38 seconds ago 2 min read
Key takeaways:
GitLab flaw CVE
The critical GitLab vulnerability, CVE-2026-19478, carries a 9.4 severity score. cve.org

Critical GitLab flaw needs no user interaction

“It's only Tuesday, and we're already dealing with a critical out-of-band security patch for GitLab instances, and yet again another reminder that supply chain attacks can take many shapes and sizes,
Knott says.
Researchers reproduce GitLab flaw within minutes.

GitLab Self-Managed users urged to update

  • 18.2 through 18.11.10
  • 19.0 through 19.0.7
  • 19.1 through 19.1.5
  • 19.2 through 19.2.3
ADVERTISEMENT
“These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately,”
the developer collaboration platform said.

GitLab awards researcher $26K bug bounty

GitLab flaw2
GitLab awarded the researcher a $26,010 bug bounty for reporting the critical GitLab flaw. hackerone.com

GitLab patches second GraphQL flaw

Stefanie Schappert
Senior Journalist
ADVERTISEMENT