Affected Systems

GitLab Community Edition (CE) and Enterprise Edition (EE) self-managed installations: all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. GitLab.com and GitLab Dedicated are already patched and not affected.

Exploitation Status

No known active exploitation as of August 18, 2026. No public exploit code available. Technical details will be disclosed around mid-November 2026 per GitLab's 90-day disclosure policy.

Business Impact

Unauthenticated attackers can remotely modify or delete public projects and user data via a GraphQL directive vulnerability. CVSS 9.4 (Critical). Exploitable over network with no credentials or user interaction required. Self-managed GitLab instances hosting public repositories face data loss and integrity risk. The specific GraphQL directive and exploitation conditions have not been disclosed, limiting defensive visibility until November 2026.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately upgrade self-managed GitLab installations to patched versions: 19.2.4, 19.1.6, 19.0.8, or 18.11.11
  • Prioritize upgrades for instances hosting public projects, as these are the primary attack surface
  • Review GitLab access logs and GraphQL query logs for anomalous unauthenticated requests targeting public projects between deployment and patching
  • Verify GitLab.com and GitLab Dedicated customers are already protected and require no action
  • Monitor GitLab's issue tracker in mid-November 2026 for technical details and adjust detection rules accordingly