CVE-2026-19478 (CVSS 9.4): GitLab GraphQL Code Injection Flaw Patched Vulnerability Report CVE-2026-19478 (CVSS 9.4): GitLab GraphQL Code Injection Flaw Patched Do Son August 18, 2026 0 TL;DR GitLab shipped an out-of-band critical patch on August 17, 2026. It fixes CVE-2026-19478, a GraphQL code... Read More Read more about CVE-2026-19478 (CVSS 9.4): GitLab GraphQL Code Injection Flaw Patched