← All labs

GitLab

CVE-2026-19650

CVE-2026-19650 GitLab GraphQL multiplex GET handling

LAB VALIDATED

OVERVIEW

Lab observed

Vulnerable19.2.2-ee.0
Patched19.2.4-ee.0

Vendor reported

Vendor-reported fixed versions

18.11.11 / 19.0.8 / 19.1.6 / 19.2.4

Only the lab versions above were independently reproduced by CVE Mapping.

LAB OBSERVED

What this lab demonstrates

The lab reproduced a state-changing GET /api/graphql multiplex request as Victim on 19.2.2-ee.0 and observed no corresponding state change in the same general test pattern on 19.2.4-ee.0.

Vulnerable baseline passed, the disposable proof issue was found as the synthetic Victim, and the patched control returned no unique proof issue. Application state—not HTTP 200 alone—is decisive.

VULNERABLE VS PATCHED RESULT

VULNERABLE

Runtime accepted and state change observed.

PATCHED

Runtime accepted and unique proof issue absent.

CI VALIDATED

Repository validation is marked true in the manifest.

DETECTION COVERAGE

Detection engineering

  • Sigmalab-validated
  • Splunklab-validated
  • Elasticlab-validated
  • osquerysupporting

EVIDENCE & TELEMETRY

Preserved and verifiable

Sanitized evidence and normalized telemetry are tracked by manifest and SHA-256 integrity files.

REPRODUCE LOCALLY

Start with the Quickstart.

Use the repository operator workflow on a disposable, localhost-only environment. The website does not embed the browser proof payload.

Open Quickstart

LIMITATIONS & SAFETY

Scope stays explicit.

The lab does not claim independent reproduction of every vendor-reported version. It requires authorized defensive use, synthetic identity, and no automated exploit command.