What is CVE-2026-19478?
CVE-2026-19478 is a vulnerability classified as Improper Control of Generation of Code ('Code Injection'), affecting GitLab (affected versions: 18.2 – < 18.11.11, 19.0 – < 19.0.8, and other affected versions). This vulnerability is rated Critical, with a CVSS score of 9.4. Public exploit code or evidence is available for this vulnerability, but that does not confirm exploitation in the wild.