GitLab Just Left the Back Door Wide Open: Why Your Code Might Be Gone
Forget the usual update cycle; GitLab just dropped an emergency patch for a massive CVSS 9.4 security hole. It’s the kind of blunder that makes you wonder if they’re testing our heart rates or just their own incompetence. Security is truly just a polite suggestion.
Security researchers hiimguardian and kreep discovered two nasty vulnerabilities in the GraphQL API that basically turned GitLab into a public playground. The heavy hitter, CVE-2026-19478, allowed any random person on the internet to modify or delete public projects without needing a login. It was essentially a 'delete everything' button that didn't even require an account.
The second issue, CVE-2026-19650, was a classic CSRF attack. By tricking a logged-in user into clicking a link, an attacker could force their browser to execute commands on the GitLab server. It’s a gentle reminder that even 'safe' HTTP methods can be twisted into something quite destructive.
The company pushed the patch out just five days after their last scheduled update, which is corporate-speak for 'we panicked.' All self-managed instances running versions 18.2 through 19.2 need to be updated to the latest security releases immediately.
In the world of modern software, 'zero trust' has clearly morphed into 'zero confidence.' When the infrastructure that hosts the world's open-source projects treats security like a patch-work quilt, one has to wonder if the entire ecosystem is being held together by nothing more than hopes, prayers, and the occasional desperate emergency release.
Source: GitLab
Comments
This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.