Description
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.9.0 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect model requests to an externally-controlled endpoint via crafted model metadata, resulting in the disclosure of Google Vertex AI or AWS Bedrock cloud service credentials.
Published: 2026-08-27
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A server‑side request forgery flaw in the GitLab AI Gateway lets an authenticated user with Duo Agent Platform privileges redirect model requests through crafted metadata to an attacker‑controlled endpoint. This can expose the credentials used by Google Vertex AI or AWS Bedrock, allowing the attacker to access cloud resources and potentially piggyback on the organization’s data environment.

Affected Systems

The flaw affects all GitLab AI Gateway releases from 18.9.0 up to 19.0.12, from 19.1 to 19.1.7, and from 19.2 to 19.2.2. Any installation of these versions is susceptible until a patch is applied.

Risk and Exploitability

The CVSS base score of 8.2 signals a high severity vulnerability. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. Exploitation requires valid Duo Agent Platform credentials, so an insider or a compromised user with that access could easily mount the attack. Once the protected endpoints are accessed, an attacker can harvest cloud service credentials and gain broad, potentially unrestricted access to cloud resources.

Generated by OpenCVE AI on August 27, 2026 at 17:21 UTC.

Remediation

Vendor Solution

Upgrade to version 19.0.12, 19.1.7, 19.2.2, 19.3.0 or newer


OpenCVE Recommended Actions

  • Upgrade the GitLab AI Gateway component to v19.0.12, v19.1.7, v19.2.2, v19.3.0 or any newer release that contains the fix.
  • Restrict Duo Agent Platform access so that only trusted administrators can modify model metadata.
  • Temporarily disable or block the AI Gateway’s ability to forward requests to external URLs until the patch is installed.

Generated by OpenCVE AI on August 27, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.9.0 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect model requests to an externally-controlled endpoint via crafted model metadata, resulting in the disclosure of Google Vertex AI or AWS Bedrock cloud service credentials.
Title Server-Side Request Forgery (SSRF) in GitLab AI Gateway
First Time appeared Gitlab
Gitlab ai-gateway
Weaknesses CWE-918
CPEs cpe:2.3:a:gitlab:ai-gateway:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab ai-gateway
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Gitlab Ai-gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-27T16:33:50.570Z

Reserved: 2026-08-14T17:04:29.105Z

Link: CVE-2026-19889

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T17:17:43.170

Modified: 2026-08-27T17:17:43.170

Link: CVE-2026-19889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T17:30:12Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)