Web Hack List

Preliminary research

CVE-2026-19478: GitLab GraphQL `@gl_introduced` validation lab

AI-collected research leads through 1 October 2026, including a bounded September review of selected social and community sources. Unranked, incomplete, not community-vetted, and subject to change.

A reproducible GitLab A/B lab explains how `@gl_introduced` strips a future field during validation but restores a resolverless field at execution, allowing graphql-ruby to call an attacker-chosen zero-argument method through `public_send`. It supplies a harmless detector, an opt-in disposable deletion proof, patched controls and a sibling multiplex-isolation test.

Record

Researcher
dinosn
Published by
GitHub
Format
Repository
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of dinosn, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .