High severity7.1NVD Advisory· Published Aug 17, 2026· Updated Sep 2, 2026
CVE-2026-19650
CVE-2026-19650
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: 18.2 <= versions < 18.11.11, 19.0 <= versions < 19.0.8, 19.1 <= versions < 19.1.6, 19.2 <= versions < 19.2.4
- Range: 18.2 <= versions < 18.11.11, 19.0 <= versions < 19.0.8, 19.1 <= versions < 19.1.6, 19.2 <= versions < 19.2.4
Patches
Vulnerability mechanics
References
2- docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/nvdVendor Advisory
- hackerone.com/reports/3903669nvdPermissions Required
News mentions
6- Critical GitLab Zero-Click Flaw Poses Mitigation ChallengesDark Reading · Aug 18, 2026
- Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)Help Net Security · Aug 18, 2026
- GitLab Patches Critical Code Injection VulnerabilitySecurityWeek · Aug 18, 2026
- Critical GitLab GraphQL Vulnerability Allow Attackers to Delete Public ProjectsCyber Security News · Aug 18, 2026
- Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public ProjectsThe Hacker News · Aug 17, 2026
- GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11GitLab Security Releases · Aug 17, 2026