Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
9/10GitLab released security updates addressing a critical GraphQL vulnerability affecting Community and Enterprise Editions that could allow unauthenticated attackers to delete or modify public projects and user data remotely. The flaw was publicly disclosed on August 17, 2026, highlighting significant risk to GitLab-hosted repositories.
