DIRAS TAKE
Urgent: public exploit code exists, so prioritize updating externally reachable GitLab instances to the listed fixed releases or block access to GraphQL endpoints until patched.
What is CVE-2026-19650?
Remote attackers can cause GitLab to run GraphQL mutations without logging in, allowing changes to data on vulnerable servers. CVE-2026-19650 affects GitLab CE/EE releases 18.2 up to but not including 18.11.11, 19.0 up to 19.0.8, 19.1 up to 19.1.6, and 19.2 up to 19.2.4. Exploitation requires network access to the instance and sending specially crafted HTTP GET requests that abuse how the application processes multiplexed GraphQL queries; no valid user credentials are required. The weakness is classified as CWE-352 (Cross-Site Request Forgery).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
Which versions of GitLab GitLab are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 18.x | 18.2 – before 18.11.11 | 18.11.11 |
| 19.x | 19.0 – before 19.0.8 | 19.0.8 |
| 19.x | 19.1 – before 19.1.6 | 19.1.6 |
| 19.x | 19.2 – before 19.2.4 | 19.2.4 |
Is CVE-2026-19650 being exploited?
Public exploit code is available.
How to fix CVE-2026-19650
- Upgrade GitLab to one of the fixed releases: 18.11.11, 19.0.8, 19.1.6, or 19.2.4 as appropriate for your branch.
- Restrict external access to GitLab GraphQL endpoints (deny or firewall access) until the update is applied.
- Monitor GitLab logs for unusual GET requests targeting /graphql or multiplex query patterns and investigate anomalies.
- Apply vendor guidance from GitLab release notes and rotate any secrets or tokens if suspicious activity is found.
Frequently asked questions
Is CVE-2026-19650 being actively exploited?
Public exploit code is available for CVE-2026-19650.
Which GitLab versions are affected by CVE-2026-19650?
GitLab CE/EE versions 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 are affected.
Is there a patch for CVE-2026-19650?
Yes; GitLab released fixes in 18.11.11, 19.0.8, 19.1.6, and 19.2.4 for the respective branches.
Does CVE-2026-19650 require authentication?
No, the vulnerability can be triggered without a valid account by sending specially crafted GET requests to vulnerable GitLab instances.
References
- nvd.nist.gov/vuln/detail/CVE-2026-19650
- cve.org/CVERecord?id=CVE-2026-19650
- gitlab.com/gitlab-org/gitlab/-/work_items/612617
- hackerone.com/reports/3903669
- docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released
- All GitLab CVEs on CVE Radar
- CVEs published in September 2026