SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP GitLab GraphQL code injection attempt
This rule looks for HTTP POST requests to the "/api/graphql" endpoint that contain the "@gl_introduced" directive together with an unusually high version number. Successful exploitation could allow an attacker to invoke arbitrary methods on server‑side objects, leading to remote code execution.
This rule fires on attempts to exploit a code injection vulnerability in GitLab web application servers via the GraphQL API.
Public information/Proof of Concept available
No known false positives
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
Vulnerability::Severity::Critical
Vulnerability::Severity::High
N/A
Not Applicable
CVE-2026-19478 |
Loading description
|