Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
GitLab has released an out-of-band security update addressing two critical vulnerabilities, CVE-2026-19478 and CVE-2062-19650, that could allow unauthenticated attackers to manipulate or delete data. The vulnerabilities stem from a code-injection flaw in GitLab's GraphQL functionality and a CSRF issue, respectively. While GitLab is withholding full technical details for 90 days, security experts recommend organizations using self-managed versions of GitLab to immediately update to the latest versions (19.2.4, 19.1.6, 19.0.8 and 18.11.11) and take proactive measures like restricting external access to GraphQL endpoints and monitoring GraphQL API logs for unusual activity.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
