Attackers don’t need credentials or user interaction to exploit the flaw which could enable supply chain attacks in self-hosted code repositories.
A critical GitLab flaw lets unauthenticated hackers modify or delete public projects and user data via GraphQL, prompting an ...
A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential ...
GitLab vulnerability CVE-2026-19478 carries a CVSS 9.4 rating, letting unauthenticated attackers remotely delete or modify public projects with no login required. An emergency patch released August 17 ...