Ai Gateway GitLab Ai Gateway

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in GitLab Ai Gateway.

By the Year

In 2026 there have been 3 vulnerabilities in GitLab Ai Gateway with an average score of 8.8 out of ten.

Year Vulnerabilities Average Score
2026 3 8.77

It may take a day or so for new Ai Gateway vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent GitLab Ai Gateway Security Vulnerabilities

GitLab AI Gateway Auth Bypass via Host Header Override (18.10-19.2.2)
CVE-2026-75871 8.2 - High - August 27, 2026

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect outbound model requests to an externally-controlled endpoint via a crafted inline flow configuration that overrides the HTTP Host header, resulting in disclosure of Google Cloud Vertex cloud service credentials and private signing keys.

SSRF

GitLab AI Gateway Auth Bypass via External Endpoint Redirect (18.9.0-19.2.2)
CVE-2026-19889 8.2 - High - August 27, 2026

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.9.0 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect model requests to an externally-controlled endpoint via crafted model metadata, resulting in the disclosure of Google Vertex AI or AWS Bedrock cloud service credentials.

SSRF

GitLab AI Gateway 18.1.618.8.0 Duo Workflow RCE via insecure template expansion
CVE-2026-1868 9.9 - Critical - February 09, 2026

GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in which AI Gateway was vulnerable to insecure template expansion of user supplied data via crafted Duo Agent Platform Flow definitions. This vulnerability could be used to cause Denial of Service or gain code execution on the Gateway. This has been fixed in versions 18.6.2, 18.7.1, and 18.8.1 of the GitLab AI Gateway.

1336

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for GitLab Ai Gateway or by GitLab? Click the Watch button to subscribe.

GitLab
Vendor

subscribe