GPU VulnDB

Database/AI/ML frameworks & serving

GitLab AI Gateway: crafted model metadata redirects model requests and discloses Vertex or Bedrock credentials

CVE-2026-19889AI/ML frameworks & servingcurated

Impact

An authenticated user with Duo Agent Platform access can pass crafted model metadata that makes the gateway send its model requests to an externally controlled endpoint, disclosing the Google Vertex AI or AWS Bedrock cloud service credentials the gateway uses. Those are instance-wide credentials, so one user with agent access walks away with the cloud identity behind everyone else's inference traffic. This is a second, distinct redirection path in the same component as CVE-2026-75871 and is fixed in the same release train, so an operator patching one should confirm they have covered both. The record scores it 8.2 with a changed scope.

Who can reach it

An authenticated GitLab user holding Duo Agent Platform access, over the network to the AI Gateway. Low privileges, no user interaction, and no administrative role required per the record.

What to do

Upgrade the AI Gateway out of the affected ranges the advisory lists - 18.9.0 through 19.0.12, 19.1 through 19.1.7, and 19.2 through 19.2.2 - to the fixed release named in the linked GitLab work item, then restart the gateway service. Rotate the Vertex AI and Bedrock credentials the gateway holds, since an upgrade does not undo any disclosure that already happened. Applies to self-managed and Dedicated instances; GitLab.com is vendor-operated.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.