Aug 182026 Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects GitLab patches CVE-2026–19478, a CVSS 9.4 GraphQL flaw that could let unauthenticated attackers modify or delete public project and user data