PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75871 GitLab CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T17:20:01.503Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects GitLab AI Gateway versions from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2. An authenticated user with Duo Agent Platform access could potentially redirect outbound model requests via a crafted inline flow configuration, overriding the HTTP Host header. This could lead to disclosure of Google Cloud Vertex cloud service credentials and private signing keys. The vulnerability could allow an authenticated user to redirect model requests to an externally-controlled endpoint, resulting in disclosure of sensitive credentials and private signing keys. To verify, defenders should review the affected versions, assess their exposure, and secure credentials. Affected stakeholders include GitLab users with AI Gateway versions from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2, administrators of Duo Agent Platform, users of Google Cloud Vertex cloud service, and security teams responsible for vulnerability management and remediation planning. They should be aware of this vulnerability and take necessary actions to protect their environments. Necessary actions include reviewing and restricting Duo Agent Platform access, updating GitLab AI Gateway versions, verifying credentials and signing keys, monitoring for suspicious model request activity, and implementing compensating controls where necessary. A coordinated effort across various roles is essential to effectively address this vulnerability and protect against potential exploitation. Multiple stakeholders, including technical teams, management, and leadership, should work together to ensure that all necessary steps are taken to secure their environments and prevent potential attacks. Effective communication and collaboration will be key to addressing this vulnerability efficiently and effectively.

Vendor
GitLab
Product
GitLab AI Gateway
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-27
Original CVE updated
2026-09-01
Advisory published
2026-08-27
Advisory updated
2026-09-01

Who should care

GitLab users with AI Gateway versions from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2, administrators of Duo Agent Platform, users of Google Cloud Vertex cloud service, and security teams responsible for vulnerability management and remediation planning should be aware of this vulnerability and take necessary actions to protect their environments. This includes reviewing and restricting Duo Agent Platform access, updating GitLab AI Gateway versions, and verifying credentials and signing keys. Security teams should also monitor for suspicious model request activity and implement compensating controls where necessary. Additionally, operators and platform administrators should assess their exposure and plan for remediation efforts accordingly. Vulnerability management teams should prioritize patching and verify the integrity of their environments. Those responsible for security operations should ensure that monitoring and detection capabilities are in place to identify potential exploitation attempts. Lastly, asset inventory managers should verify that affected components are identified and tracked for remediation. This multi-faceted approach ensures comprehensive coverage and minimizes potential risks associated with this vulnerability. Reviewing compensating controls and asset inventories will further enhance security posture against potential threats. Therefore, a coordinated effort across various roles is essential to effectively address this vulnerability and protect against potential exploitation. The involvement of multiple stakeholders is crucial for successful mitigation and remediation efforts. By working together, organizations can ensure that all necessary steps are taken to secure their environments and prevent potential attacks. This includes not only technical teams but also management and leadership, as their support and resources are vital for successful remediation. Effective communication and collaboration will be key to addressing this vulnerability efficiently and effectively. In conclusion, a broad range of stakeholders should care about this vulnerability and contribute to its mitigation and remediation. Their collective efforts can

Technical summary

The vulnerability in GitLab AI Gateway could allow an authenticated user with Duo Agent Platform access to redirect outbound model requests to an externally-controlled endpoint via a crafted inline flow configuration, resulting in disclosure of Google Cloud Vertex cloud service credentials and private signing keys. This vulnerability affects GitLab AI Gateway versions from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2. The vulnerability could allow an authenticated user to redirect model requests to an externally-controlled endpoint, resulting in disclosure of sensitive credentials and private signing keys. An attacker could exploit this vulnerability by crafting an inline flow configuration that overrides the HTTP Host header, allowing them to redirect model requests to an externally-controlled endpoint.

Defensive priority

Authenticated users with Duo Agent Platform access could potentially redirect model requests to an externally-controlled endpoint, disclosing Google Cloud Vertex cloud service credentials and private signing keys.

Recommended defensive actions

  • Review and restrict Duo Agent Platform access to minimize potential impact.
  • Update GitLab AI Gateway to a version outside the vulnerable range.
  • Monitor for suspicious model request activity.
  • Verify and secure Google Cloud Vertex cloud service credentials and private signing keys.
  • Implement compensating controls to detect and prevent potential redirection of model requests.

Evidence notes

The vulnerability affects GitLab AI Gateway versions from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2. An authenticated user with Duo Agent Platform access could potentially redirect outbound model requests via a crafted inline flow configuration, overriding the HTTP Host header. This could lead to disclosure of Google Cloud Vertex cloud service credentials and private signing keys. To verify, defenders should review the affected versions, assess their exposure, and secure credentials.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75871 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75871

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75871 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75871

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.