Hackers started exploiting CVE-2026-19478, a critical, unauthenticated GitLab vulnerability, shortly after public disclosure.
A critical GitLab flaw lets unauthenticated hackers modify or delete public projects and user data via GraphQL, prompting an ...
Tech Times on MSN
GitLab emergency patch: Third GraphQL flaw of 2026 lets unauthenticated attackers delete projects
GitLab vulnerability CVE-2026-19478 carries a CVSS 9.4 rating, letting unauthenticated attackers remotely delete or modify public projects with no login required. An emergency patch released August 17 ...
GitLab CVE-2026-19478 is under active exploitation, with unauthenticated attacks able to modify or delete public projects ...
Attackers don’t need credentials or user interaction to exploit the flaw which could enable supply chain attacks in self-hosted code repositories.
Unlock the full InfoQ experience by logging in! Stay updated with your favorite authors and topics, engage with content, and download exclusive resources. David Chisnall discusses how the CHERI ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results