High severity7.1NVD Advisory· Published Aug 17, 2026· Updated Aug 17, 2026
CVE-2026-19650
CVE-2026-19650
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <18.11.11, <19.0.8, <19.1.6, <19.2.4
- Range: <18.11.11, <19.0.8, <19.1.6, <19.2.4
Patches
Vulnerability mechanics
References
2News mentions
2- Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public ProjectsThe Hacker News · Aug 17, 2026
- GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11GitLab Security Releases · Aug 17, 2026