Attackers can forge a merge record so it looks like the fix landed — GitLab's flaw went from patch to exploitation in days
2026-08-21Security
watchTowr reproduced CVE-2026-19478 within minutes of disclosure and then saw it used against its own honeypots. Beyond deleting repositories, it lets an attacker fabricate merge records and ban maintainers — which means the log that says a security fix was applied can itself be the lie.