Dossier
code injection
Coverage of code injection in the Nexus archive.
- GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
A newly disclosed security flaw in GitLab, identified as CVE-2026-19478, is under active exploitation shortly after public disclosure. This vulnerability is a code injection that permits an unauthenticated attacker to modify or delete publicly accessible projects and rewrite their data on GitLab under specific conditions.