NCSC-2026-0303 [1.00] [M/H] Vulnerabilities Fixed in GitLab by GitLab Inc.
GitLab Inc. has fixed vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE). The vulnerabilities are present in GitLab's GraphQL implementation. A first vulnerability made it possible for unauthenticated users to perform unauthorized modifications or deletions on public projects and user data through a GraphQL directive. A second vulnerability allowed unauthenticated users to perform mutations through GET requests due to improper validation of GraphQL multiplex queries, where mutation operations were not correctly restricted. This allows unauthorized parties to make unauthorized changes to the state of the server.
CSIRTS triage
- What
- Two GraphQL vulnerabilities allow unauthenticated users to perform unauthorized modifications and deletions on public projects via an improper directive and to execute mutations through GET requests due to insufficient multiplex query validation.
- Who is affected
- All GitLab CE and EE deployments with public projects and GraphQL enabled are affected.
- Urgency
- High urgency; unauthenticated attackers can modify or delete data without authentication.
- Action
- Update GitLab to the patched version that fixes the GraphQL directive and multiplex query validation issues.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch GitLab Community Edition and Enterprise Edition
Get an email when a new GitLab Community Edition and Enterprise Edition advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0303
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-19478 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19650 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-19650: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.1…nvd
- criticalCVE-2026-19478: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.1…nvd
- criticalGitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11gitlab
- criticalGitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11gitlab
Recent advisories for GitLab by GitLab
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-19650: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.1…nvd · 2026-08-17
- criticalCVE-2026-19478: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.1…nvd · 2026-08-17
- mediumCVE-2026-16049: Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to ve…nvd · 2026-08-17
- criticalGitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11gitlab · 2026-08-17
- criticalGitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11gitlab · 2026-08-17
- unknownGitLab security advisory (AV26-814)cccs · 2026-08-13
More from NCSC-NL Advisories
- unknownNCSC-2026-0304 [1.00] [M/H] ZeroDay Vulnerability Fixed in GeoTools by OpenGeo2026-08-18
- unknownNCSC-2026-0302 [1.00] [M/H] Vulnerabilities patched in SAP Commerce Cloud Data Hub Adapter2026-08-15
- unknownNCSC-2026-0301 [1.00] [M/H] Vulnerabilities patched in IBM i operating system by IBM2026-08-14
- unknownNCSC-2026-0300 [1.00] [M/H] Vulnerabilities patched in Fortinet FortiWeb2026-08-13
- unknownNCSC-2026-0299 [1.00] [M/H] Vulnerability patched in Fortinet FortiManager2026-08-13