P.01CVE-2026-19478: GitLab's Critical GraphQL Flaw Lets Anyone Delete Your Public Projects
An unauthenticated attacker can inject code through a GitLab GraphQL directive and delete or modify public projects and user data. CVSS 9.4, patched in 19.2.4. Here's what's affected and how to check your instance.



































































