daily cyber × ai intelligence

index

tagged

[CVE-2026-19478]

3 editions · 3 items

August 18, 2026

  • GitLab CVE-2026-19478 enables unauthenticated modification or deletion of public projects and user data. The critical GraphQL code-injection flaw affects self-managed GitLab CE and EE, carries a CVSS score of 9.4, and can be triggered with one request under the vulnerable conditions. watchTowr reproduced it within minutes; no public exploit was available at the time. Operators should upgrade or restrict access to /api/graphql, with Dark Reading noting that limited technical detail complicates retrospective detection. The Hacker News has the patch overview. · Vulnerabilities & Exploits

in Three Fast-Moving Flaws Put GitLab and AI Infrastructure on Alert