cbcvebase.

Gitlab Ai Gateway vulnerabilities

3 known vulnerabilities affecting gitlab/gitlab_ai_gateway.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1

Vulnerabilities

Page 1 of 1
CVE-2026-1868P2CRITICALCVSS 9.9≥ 18.1.6, < 18.6.2≥ 18.7.0, < 18.7.1+1 more2026-02-09
CVE-2026-1868 [CRITICAL] CWE-1336 CVE-2026-1868: GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway aff GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in which AI Gateway was vulnerable to insecure template expansion of user supplied data via crafted Duo Agent Platform Flow definitions. This vulnerabilit
nvd
CVE-2026-75871P3CRITICALCVSS 9.6≥ 18.10, < 19.0.12≥ 19.1, < 19.1.7+1 more2026-08-27
CVE-2026-75871 [CRITICAL] CWE-918 CVE-2026-75871: GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of t GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect outbound model requests to an externally-controlled endpoint via a crafted inline flow c
nvd
CVE-2026-19889P3HIGHCVSS 8.2≥ 18.9, < 19.0.12≥ 19.1, < 19.1.7+1 more2026-08-27
CVE-2026-19889 [HIGH] CWE-918 CVE-2026-19889: GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of t GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.9.0 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect model requests to an externally-controlled endpoint via crafted model metadata, resulting i
nvd
Gitlab Ai Gateway vulnerabilities | cvebase