As cited
Copy frozen at (site build).
NCSC-2026-0303 [1.01] [M/H] Kwetsbaarheden verholpen in GitLab door GitLab Inc.
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
NCSC-2026-0303 [1.01] [M/H] Kwetsbaarheden verholpen in GitLab door GitLab Inc.
GitLab Inc. patched multiple vulnerabilities in GitLab Community Edition and Enterprise Edition affecting the GraphQL implementation. Unauthenticated attackers could exploit these flaws to perform unauthorized modifications or deletions on public projects and user data through improper validation of GraphQL directives and multiplex queries. Public proof-of-concept code is now available, significantly increasing the risk of active exploitation.
Why it matters: Organizations running GitLab CE or EE must apply patches immediately, as unauthenticated attackers can modify or delete data on public projects and server state without valid credentials.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
NCSC-2026-0303 [1.01] [M/H] Kwetsbaarheden verholpen in GitLab door GitLab Inc.
GitLab Inc. patched multiple vulnerabilities in GitLab Community Edition and Enterprise Edition affecting the GraphQL implementation. Unauthenticated attackers could exploit these flaws to perform unauthorized modifications or deletions on public projects and user data through improper validation of GraphQL directives and multiplex queries. Public proof-of-concept code is now available, significantly increasing the risk of active exploitation.
Why it matters: Organizations running GitLab CE or EE must apply patches immediately, as unauthenticated attackers can modify or delete data on public projects and server state without valid credentials.
- Source published
- First seen by Cybersecurity Tracker