Database/AI/ML frameworks & serving
GitLab AI Gateway: crafted inline flow config overrides the HTTP Host header and leaks Vertex credentials
Impact
An authenticated user with Duo Agent Platform access can supply an inline flow configuration that overrides the outbound HTTP Host header, steering the gateway's model requests to an endpoint the attacker controls. The requests carry the gateway's own Google Cloud Vertex service credentials and private signing keys, so the attacker collects the secrets the gateway uses on behalf of every user of that instance. On a self-managed GitLab those credentials are typically the shared identity a whole organization's AI traffic runs under, and the signing keys extend the blast radius past a single API bill to anything that trusts tokens the gateway issues. The record scores it 8.2 with a changed scope.
Who can reach it
An authenticated GitLab user who has been granted Duo Agent Platform access, reaching the AI Gateway over the network. No administrative role is required - the record specifies low privileges and no user interaction.
What to do
Upgrade the AI Gateway past the affected ranges the advisory lists - 18.10 through 19.0.12, 19.1 through 19.1.7, and 19.2 through 19.2.2 - to the fixed release named in the linked GitLab work item, and restart the gateway service; the fix is a service upgrade, not a fleet-wide reboot. Because credentials may already have been exfiltrated on an exposed instance, rotate the Vertex service account credentials and any private signing keys the gateway holds rather than treating the upgrade as sufficient. GitLab.com is operated by the vendor; this action item is for self-managed and Dedicated deployments.
References
Related entries
- Gradio: Command injectionCVE-2023-6572 · GradioHigh
- LangChain: Directory traversal via the template path parameterCVE-2024-28088 · LangChainHigh
- JupyterHub: Malicious subdomain tricks a userCVE-2024-28233 · JupyterHubHigh
- LiteLLM: Arbitrary file deletion via `/audio/transcriptions`CVE-2024-4888 · LiteLLMHigh
- MLflow (REST API): DNS rebinding — no Origin header validationCVE-2025-14279 · MLflow (REST API)High
- NVIDIA Triton (Python backend): Out-of-bounds write in the Python backendCVE-2025-23318 · NVIDIA Triton (Python backend)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.