This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
Critical Vulnerability in GitLab Platform (CVE-2026-19478)
A unauthenticated code injection vulnerability has been identified in the GitLab CE/EE platform (CVSS score 9.4), which is actively being exploited in cyberattacks. The vulnerability allows an attacker to modify or delete public projects, overwrite repository data, and block project maintainers without authentication. The attack is carried out via the GraphQL API. Affected versions include GitLab CE/EE 18.2 to 18.11.10; 19.0 to 19.0.7; 19.1 to 19.1.5; 19.2 to 19.2.3. https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/