NCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.
GitLab Inc. has patched vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE). The vulnerabilities are located in GitLab's GraphQL implementation. A first vulnerability allowed unauthenticated users to perform unauthorized modifications or deletions on public projects and user data via a GraphQL directive. A second vulnerability allowed unauthenticated users to perform mutations via GET requests due to improper validation of GraphQL multiplex queries, where mutation operations were not correctly restricted. This allows unauthorized parties to make unauthorized changes to the server state. Update: Public PoC code is now available, significantly increasing the risk of active abuse. The NCSC advises that systems not yet updated should apply the updates as quickly as possible.
CSIRTS triage
- What
- Unauthenticated users can perform unauthorized modifications and deletions on public projects via GraphQL directives and execute mutations via GET requests due to improper GraphQL multiplex query validation.
- Who is affected
- All GitLab CE and EE deployments are affected; public PoC code is now available.
- Urgency
- Critical; public exploit code exists and NCSC advises immediate patching to prevent active abuse.
- Action
- Apply GitLab security patches immediately to all CE and EE instances.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch GitLab Community Edition and Enterprise Edition
Get an email when a new GitLab Community Edition and Enterprise Edition advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0303
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-194786.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 93% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-196500.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-19478 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19650 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalGitLab security advisory (AV26-827) – Update 1cccs
- critical[NEW] [high] GitLab: Multiple vulnerabilities allow file manipulationcert-bund
- unknownGitLab Multiple Vulnerabilitieshkcert
- unknownNCSC-2026-0303 [1.00] [M/H] Vulnerabilities Fixed in GitLab by GitLab Inc.ncsc-nl
- unknownMultiple vulnerabilities in GitLab (August 18, 2026)cert-fr-avis
- highCVE-2026-19650: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.1…nvd
- criticalCVE-2026-19478: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.1…nvd
- criticalGitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11gitlab
- criticalGitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11gitlab
Recent advisories for GitLab by GitLab
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-10053: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6,…nvd · 2026-08-23
- criticalGitLab security advisory (AV26-827) – Update 1cccs · 2026-08-21
- unknownCVE-2026-0830 - Command Injection in Kiro GitLab Merge Request Helperaws · 2026-08-20
- critical[NEW] [high] GitLab: Multiple vulnerabilities allow file manipulationcert-bund · 2026-08-20
- unknownGitLab Multiple Vulnerabilitieshkcert · 2026-08-19
- unknownNCSC-2026-0303 [1.00] [M/H] Vulnerabilities Fixed in GitLab by GitLab Inc.ncsc-nl · 2026-08-18
More from NCSC-NL Advisories
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21
- unknownNCSC-2026-0322 [1.00] [M/H] Vulnerabilities fixed in Splunk Enterprise by Splunk2026-08-21