Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5940 articles · 214609 vulns · 37/41 feeds (7d)
← Back to list
8.2
CVE-2026-75871PATCHED
GitLab · GitLab AI Gateway

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an a

Description

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect outbound model requests to an externally-controlled endpoint via a crafted inline flow configuration that overrides the HTTP Host header, resulting in disclosure of Google Cloud Vertex cloud service credentials and private signing keys.

Affected Products

VendorProductVersions
GitLabGitLab AI Gateway18.10, 19.1, 19.2

References

  • https://gitlab.com/gitlab-org/gitlab/-/work_items/616990
  • https://hackerone.com/reports/3945100(technical-description, exploit, permissions-required)

Related News (1 articles)

Tier C
VulDB15d ago
CVE-2026-75871 | GitLab up to 19.0.11/19.1.6/19.2.1 AI Gateway redirect
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.2 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
19.0.1219.1.719.2.2
CWECWE-918
PublishedAug 27, 2026
Last enriched15d ago
Trending Score4
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-85706EXPKEV
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
Trending: 138
CRITICALCVE-2026-19478
Improper Control of Generation of Code ('Code Injection') in GitLab
Trending: 41
CRITICALCVE-2026-87719
Deserialization of Untrusted Data in GitLab
Trending: 41
HIGHCVE-2026-19650
Cross-Site Request Forgery (CSRF) in GitLab
Trending: 27
HIGHCVE-2026-18252
Inclusion of Functionality from Untrusted Control Sphere in GitLab
Trending: 5

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 27, 2026
Patch Available
Aug 27, 2026
Discovered by ZDM
Aug 27, 2026