Description
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect outbound model requests to an externally-controlled endpoint via a crafted inline flow configuration that overrides the HTTP Host header, resulting in disclosure of Google Cloud Vertex cloud service credentials and private signing keys.
Published: 2026-08-27
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Credential disclosure via SSRF
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the GitLab AI Gateway component and allows an authenticated user that has Duo Agent Platform access to construct a crafted inline flow configuration that overrides the HTTP Host header. This manipulation enables the user to redirect outbound model requests to an externally‑controlled endpoint, resulting in the disclosure of Google Cloud Vertex cloud service credentials and private signing keys. The primary impact is the compromise of sensitive credentials, exposing integrated cloud services to unauthorized access.

Affected Systems

Affected vendors include GitLab, specifically the GitLab AI Gateway product. All versions from 18.10 up to 19.0.12, from 19.1 up to 19.1.7, and from 19.2 up to 19.2.2 are vulnerable.

Risk and Exploitability

The CVSS score of 8.2 designates this as a High‑severity vulnerability. The EPSS score is not available, and it is not listed in the CISA KEV catalog. The likely attack vector requires authentication and Duo Agent Platform permissions, meaning an insider or compromised internal user could exploit the flaw. Exploitation involves crafting an inline flow configuration, making the influence path both technically feasible and potentially destructive.

Generated by OpenCVE AI on August 27, 2026 at 17:36 UTC.

Remediation

Vendor Solution

Upgrade to version 19.0.12, 19.1.7, 19.2.2, 19.3.0 or newer


OpenCVE Recommended Actions

  • Upgrade the GitLab AI Gateway to version 19.0.12, 19.1.7, 19.2.2, 19.3.0 or newer as provided by the vendor
  • Verify that only authorized Duo Agent Platform users have access to the inline flow configuration mechanism
  • Restrict or monitor outbound model requests to ensure they do not reach unauthorized external endpoints

Generated by OpenCVE AI on August 27, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Gitlab gitlab
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab gitlab

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect outbound model requests to an externally-controlled endpoint via a crafted inline flow configuration that overrides the HTTP Host header, resulting in disclosure of Google Cloud Vertex cloud service credentials and private signing keys.
Title Server-Side Request Forgery (SSRF) in GitLab AI Gateway
First Time appeared Gitlab
Gitlab ai-gateway
Weaknesses CWE-918
CPEs cpe:2.3:a:gitlab:ai-gateway:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab ai-gateway
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Gitlab Ai-gateway Gitlab
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-27T18:58:34.704Z

Reserved: 2026-08-18T12:06:50.452Z

Link: CVE-2026-75871

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-27T17:20:01.503

Modified: 2026-09-01T20:32:55.990

Link: CVE-2026-75871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T18:30:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)