{
  "id": 1858224,
  "title": "Two GitLab GraphQL Vulnerabilities: Unauthenticated Data Tampering and CSRF",
  "url": "https://urgent.news/2026/08/19/two-gitlab-graphql-vulnerabilities-unauthenticated-data-tampering-and",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-19T03:30:09.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/two-gitlab-graphql-vulnerabilities-unauthenticated-data-tampering-and-csrf-2m53"
  },
  "original_language": "en",
  "account": "GitLab released updates for four versions of its software to address two critical security vulnerabilities. The first flaw, CVE-2026-19478, allows unauthenticated attackers to directly send crafted GraphQL requests to the self-managed GitLab instance without any authentication or user interaction. This can lead to unauthorized modification or deletion of public project or user data, potentially causing ripple effects on the overall software supply chain or user data. The second vulnerability, CVE-2026-19650, is a CSRF attack that tricks a user into clicking a specially crafted link. The GET request sent from the user's browser to the GraphQL multiplex handler fails validation, resulting in the execution of a mutation and subsequent data modification or deletion. Both vulnerabilities affect self-managed installations of GitLab CE/EE, and GitLab.com and GitLab Dedicated are already patched. Users are not required to take any immediate action as GitLab will keep specific details of the vulnerabilities private for 90 days.",
  "summary": "Two GitLab GraphQL Vulnerabilities: Unauthenticated Data Tampering and CSRF 1. Basic Information Article Title : GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11 Publisher : GitLab Publication Date : 2026-08-17 Severity : High Original Source : GitLab Related Sources : Dark Reading , SecurityWeek Related Malware / Threat Groups : None / Unidentified Primary Target : CVE-2026-19478…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}