Attackers don’t need credentials or user interaction to exploit the flaw which could enable supply chain attacks in self-hosted code repositories.
A critical GitLab flaw lets unauthenticated hackers modify or delete public projects and user data via GraphQL, prompting an ...
A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential ...
Tech Times on MSN
GitLab emergency patch: Third GraphQL flaw of 2026 lets unauthenticated attackers delete projects
GitLab vulnerability CVE-2026-19478 carries a CVSS 9.4 rating, letting unauthenticated attackers remotely delete or modify public projects with no login required. An emergency patch released August 17 ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results