GitLabCVE-2026-19889
GitLab AI Gateway: server-side request forgery
High8.2CVE-2026-19889 · Published Aug 27, 2026 · updated Aug 28, 2026
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.9.0 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect model requests to an externally-controlled endpoint via crafted model metadata, resulting in the disclosure of Google Vertex AI or AWS Bedrock cloud service credentials.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GitLab AI Gateway Product | >= 18.9, < 19.0.12 | 19.0.12 |
| >= 19.1, < 19.1.7 | 19.1.7 | |
| >= 19.2, < 19.2.2 | 19.2.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-918
More GitLab advisories
All GitLab| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 27 | GitLab AI Gateway: server-side request forgery | High8.2 | 19.0.12+2 more |
| Aug 26 | GitLab: improper authorization | Low3.5 | 19.1.7+2 more |
| Aug 26 | GitLab: denial of service | Medium6.5 | 19.1.7+2 more |
| Aug 26 | GitLab: improper authorization | Medium5.5 | 19.1.7+2 more |
| Aug 26 | GitLab: untrusted functionality included | High7.3 | 19.1.7+2 more |
| Aug 26 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1... | Medium4.3 | 19.1.7+2 more |