GPU VulnDB

Database/Control plane, storage & DevOps

GitLab: an unauthenticated GraphQL directive can modify or delete public projects and user data

CVE-2026-19478Control plane, storage & DevOpscurated

Impact

Under conditions GitLab does not detail, an unauthenticated request using a GraphQL directive modifies or deletes public projects and user data. On a self-hosted GitLab that is the system of record for pipeline definitions, infrastructure-as-code, and container build recipes for the fleet, so this is both a data-destruction event and a path to tampering with what CI runners execute on GPU nodes. Integrity and availability are rated high while confidentiality is only low, so the realistic outcome is destruction and modification rather than mass data theft. Affected: 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.

Who can reach it

Anyone who can reach the GitLab web endpoint. No authentication, no user interaction. Internet-facing instances are exposed directly; internal-only instances are exposed to anyone on the corporate or management network.

What to do

Upgrade to 18.11.11, 19.0.8, 19.1.6, or 19.2.4 as matches your branch. This is a control-plane package upgrade and service restart (for Omnibus, reconfigure and restart), costing a short GitLab outage — no node drain, no impact on running GPU jobs, though queued pipelines will pause for the duration.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.