---
title: "GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11"
url: https://daily.dev/posts/gitlab-critical-patch-release-19-2-4-19-1-6-19-0-8-18-11-11-ia6q2kfti
source_url: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released
type: article
source: "GitLab"
published: 2026-08-17T20:31:02.772Z
updated: 2026-08-22T23:49:21.922Z
tags: ["security", "graphql", "gitlab"]
reading_time: 3
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11

**[GitLab](https://daily.dev/sources/gitlab)** · 3 min read · 0 upvotes · 0 comments

## Summary

GitLab released critical patch versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11 for Community Edition and Enterprise Edition to fix high-severity security vulnerabilities. CVE-2026-19478 is a code injection issue via a GraphQL directive (CVSS 9.4) that could let an unauthenticated user remotely modify or delete public projects and user data. CVE-2026-19650 is a CSRF issue in the GraphQL multiplex query handler (CVSS 7.1) allowing mutation execution via GET requests. All self-managed installations from version 18.2 up to these patches are affected and should upgrade immediately; GitLab.com and GitLab Dedicated are already patched.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released>

## Questions this post answers

### What versions of GitLab fix CVE-2026-19478 and CVE-2026-19650?

GitLab 19.2.4, 19.1.6, 19.0.8, and 18.11.11 fix both vulnerabilities. CVE-2026-19478 is a code injection issue via a GraphQL directive (CVSS 9.4) that could let an unauthenticated user remotely modify or delete public projects and user data. CVE-2026-19650 is a CSRF issue in the GraphQL multiplex query handler (CVSS 7.1) allowing mutation execution via GET requests. Affected versions range from 18.2 up to these patched releases.

_daily.dev helps self-managed GitLab admins keep up with critical security patches like this one._

### Do I need to upgrade my GitLab instance immediately after this critical patch release?

Yes, if you run a self-managed GitLab installation between version 18.2 and the patched releases (19.2.4, 19.1.6, 19.0.8, 18.11.11), you should upgrade immediately due to a critical CVSS 9.4 vulnerability. GitLab.com and GitLab Dedicated are already running the patched version, so those customers do not need to take action.

_Track urgent security releases like this GitLab patch on daily.dev before they hit your infrastructure._

## Similar posts on daily.dev

- [GitLab Patch Release: 19.0.2, 18.11.5, 18.10.8](https://daily.dev/posts/gitlab-patch-release-19-0-2-18-11-5-18-10-8-fmukjse7k) · GitLab · 0 upvotes · 0 comments
- [GitLab Patch Release: 19.0.1, 18.11.4, 18.10.7](https://daily.dev/posts/gitlab-patch-release-19-0-1-18-11-4-18-10-7-zr6cdslky) · GitLab · 0 upvotes · 0 comments
- [GitLab Patch Release: 19.1.1, 19.0.3, 18.11.6](https://daily.dev/posts/gitlab-patch-release-19-1-1-19-0-3-18-11-6-flm7cmppy) · GitLab · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#graphql](https://daily.dev/tags/graphql), [#gitlab](https://daily.dev/tags/gitlab)

[View this post on daily.dev](https://daily.dev/posts/gitlab-critical-patch-release-19-2-4-19-1-6-19-0-8-18-11-11-ia6q2kfti)
