GitLab GraphQL Flaw Puts Public Projects at Risk
GitLab patched CVE-2026-19478, a critical GraphQL directive issue that could let unauthenticated attackers alter or delete public projects and user data; self-managed CE/EE operators should update to the fixed releases.