CVE-2026-19478 Can Alter or Delete Public Projects Without Authentication. Researchers detected active exploitation of CVE-2026-19478, a critical GitLab code injection flaw that lets unauthenticated attackers alter public projects, forge merge records or delete repositories, creating a potential path to software supply-chain compromise.
First seen on govinfosecurity.com
Jump to article: www.govinfosecurity.com/gitlab-code-injection-flaw-exploited-in-wild-a-32606
![]()

