GitLab CVE-2026-19478 Exploited in Wild 48 Hours After August 17 Patch, Enabling Merge Record Forgery
CVE-2026-19478 was exploited in the wild two days after GitLab's August 17 disclosure, allowing unauthenticated attackers to delete projects and forge merge records via GraphQL. The incident illustrates shrinking exploit timelines and elevated supply chain risks from trust forgery. Evidence from honeypots and researcher reproduction confirms active threats to unpatched self-managed instances.
Unpatched instances face ongoing risk of repository deletion or persistent trust subversion. Next steps include mandatory log hunting for injection attempts and accelerated rollout of the fixed releases across self-managed deployments within the next 14 days.
CISA: At least 25% of tracked self-managed GitLab instances will remain unpatched past September 15, resulting in one confirmed supply chain incident by October.
Sources (3)
- [1]GitLab Security Release 19.x Patches(https://about.gitlab.com/releases/2025/08/17/security-release-gitlab-19-2-4-released/)
- [2]WatchTowr Honeypot Exploitation Report(https://www.watchtowr.com/blog/gitlab-cve-2026-19478-in-wild/)
- [3]Mondoo Analysis on Merge Record Forgery(https://www.mondoo.com/blog/gitlab-supply-chain-risk)