GitLab released critical patch versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11 for Community Edition and Enterprise Edition to fix high-severity security vulnerabilities. CVE-2026-19478 is a code injection issue via a GraphQL directive (CVSS 9.4) that could let an unauthenticated user remotely modify or delete public projects and user data. CVE-2026-19650 is a CSRF issue in the GraphQL multiplex query handler (CVSS 7.1) allowing mutation execution via GET requests. All self-managed installations from version 18.2 up to these patches are affected and should upgrade immediately; GitLab.com and GitLab Dedicated are already patched.

3m read timeFrom docs.gitlab.com
Post cover image
Table of contents
Security fixesImportant notes on upgradingUpdatingReceive Patch Notifications

Questions this post answers

What versions of GitLab fix CVE-2026-19478 and CVE-2026-19650?

GitLab 19.2.4, 19.1.6, 19.0.8, and 18.11.11 fix both vulnerabilities. CVE-2026-19478 is a code injection issue via a GraphQL directive (CVSS 9.4) that could let an unauthenticated user remotely modify or delete public projects and user data. CVE-2026-19650 is a CSRF issue in the GraphQL multiplex query handler (CVSS 7.1) allowing mutation execution via GET requests. Affected versions range from 18.2 up to these patched releases. daily.dev helps self-managed GitLab admins keep up with critical security patches like this one.

Do I need to upgrade my GitLab instance immediately after this critical patch release?

Yes, if you run a self-managed GitLab installation between version 18.2 and the patched releases (19.2.4, 19.1.6, 19.0.8, 18.11.11), you should upgrade immediately due to a critical CVSS 9.4 vulnerability. GitLab.com and GitLab Dedicated are already running the patched version, so those customers do not need to take action. Track urgent security releases like this GitLab patch on daily.dev before they hit your infrastructure.

248 Impressions