Rule Category

SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.

Alert Message

SERVER-WEBAPP GitLab GraphQL code injection attempt

Rule Explanation

This rule looks for HTTP POST requests to the "/api/graphql" endpoint that contain the "@gl_introduced" directive together with an unusually high version number. Successful exploitation could allow an attacker to invoke arbitrary methods on server‑side objects, leading to remote code execution.

What To Look For

This rule fires on attempts to exploit a code injection vulnerability in GitLab web application servers via the GraphQL API.

Known Usage

Public information/Proof of Concept available

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application

Vulnerability::Severity::Critical

Vulnerability::Severity::High

CVE

Additional Links

Rule Vulnerability

N/A

Not Applicable

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2026-19478
Loading description