# GitLab Patches CSRF, Data Integrity Flaws

Published: 2026-08-18 · Severity: elevated · Sectors: technology
Canonical: https://vorant.io/reports/1f277511-377e-51a0-91ea-fd0f2175ae55/gitlab-patches-csrf-data-integrity-flaws

> GitLab CE/EE has multiple vulnerabilities including CSRF and data integrity issues, fixed in versions 19.0.8, 19.1.6, 19.2.4, and 18.11.11.

ANSSI (CERT-FR) published an advisory covering multiple vulnerabilities in GitLab Community Edition and Enterprise Edition. The flaws allow an attacker to compromise data integrity and to perform Cross-Site Request Forgery (CSRF) attacks, enabling illegitimate requests to be injected by bouncing off a victim's session.

Two CVEs are referenced: CVE-2026-19478 and CVE-2026-19650. Affected versions span the 19.0.x, 19.1.x, and 19.2.x branches prior to 19.0.8, 19.1.6, and 19.2.4 respectively, as well as all versions prior to 18.11.11. GitLab has released a security bulletin dated 17 August 2026 with corrective patches, and organizations running affected versions are advised to update promptly per the vendor's guidance.

No evidence of active exploitation is mentioned in the advisory. This is a routine vendor patch notice rather than an active-threat report, and the risk profile is consistent with standard vulnerability management processes for GitLab deployments.

## Mentioned in this report

- Vulnerabilities: CVE-2026-19478 (templated), CVE-2026-19650

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1037

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1f277511-377e-51a0-91ea-fd0f2175ae55/gitlab-patches-csrf-data-integrity-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
