Preliminary research
CVE-2026-19478: GitLab GraphQL `@gl_introduced` validation lab
AI-collected research leads through 1 October 2026, including a bounded September review of selected social and community sources. Unranked, incomplete, not community-vetted, and subject to change.
A reproducible GitLab A/B lab explains how `@gl_introduced` strips a future field during validation but restores a resolverless field at execution, allowing graphql-ruby to call an attacker-chosen zero-argument method through `public_send`. It supplies a harmless detector, an opt-in disposable deletion proof, patched controls and a sibling multiplex-isolation test.
Record
- Researcher
- dinosn
- Published by
- GitHub
- Format
- Repository
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of dinosn, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .