GitLab bundles a zero-click GraphQL flaw with a CSRF bug, and only one needs a victim
CVE-2026-19478 needs no login and no click. CVE-2026-19650 needs a user to open a link. Self-managed operators on 18.11, 19.0, 19.1 and 19.2 have to patch anyway.
Reality
- Evidence58
- Adoption24
- Hype gap+12
- Incentives52
- Confidence55