THEMETASEC

Cybersecurity News, Aggregated

GitLab Patches Critical Unauthenticated GraphQL Vulnerability

Security Affairs · 58 minutes ago Vuln

GitLab patched a critical GraphQL flaw that let unauthenticated attackers remotely modify or delete public projects on self-managed servers. GitLab pushed out an emergency patch this week to address a critical flaw, tracked as CVE-2026-19478 (CVSS score of 9.4), that could let an attacker with zero credentials remotely modify or delete public projects and user […]

Read full story at Security Affairs →