GPU VulnDB

Database/AI/ML frameworks & serving

GitLab AI Gateway: crafted inline flow config overrides the HTTP Host header and leaks Vertex credentials

CVE-2026-75871AI/ML frameworks & servingcurated

Impact

An authenticated user with Duo Agent Platform access can supply an inline flow configuration that overrides the outbound HTTP Host header, steering the gateway's model requests to an endpoint the attacker controls. The requests carry the gateway's own Google Cloud Vertex service credentials and private signing keys, so the attacker collects the secrets the gateway uses on behalf of every user of that instance. On a self-managed GitLab those credentials are typically the shared identity a whole organization's AI traffic runs under, and the signing keys extend the blast radius past a single API bill to anything that trusts tokens the gateway issues. The record scores it 8.2 with a changed scope.

Who can reach it

An authenticated GitLab user who has been granted Duo Agent Platform access, reaching the AI Gateway over the network. No administrative role is required - the record specifies low privileges and no user interaction.

What to do

Upgrade the AI Gateway past the affected ranges the advisory lists - 18.10 through 19.0.12, 19.1 through 19.1.7, and 19.2 through 19.2.2 - to the fixed release named in the linked GitLab work item, and restart the gateway service; the fix is a service upgrade, not a fleet-wide reboot. Because credentials may already have been exfiltrated on an exposed instance, rotate the Vertex service account credentials and any private signing keys the gateway holds rather than treating the upgrade as sufficient. GitLab.com is operated by the vendor; this action item is for self-managed and Dedicated deployments.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.