GitLab Code Injection Flaw (CVE-2026-19478) Under Active Exploitation
A recently disclosed critical code injection vulnerability in GitLab (CVE-2026-19478, CVSS 9.4) is being actively exploited within days of its public disclosure. This flaw allows unauthenticated attackers to modify or delete publicly accessible GitLab projects and rewrite their data under specific conditions. Organizations using self-managed GitLab instances face significant mitigation challenges due to the lack of detailed technical information.