Sceawere

Vulnerability Detail

CVE-2026-75871UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GitLab AI Gateway SSRF Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
1h ago
Vendor
GitLab
Product
GitLab AI Gateway
Attack Type
CWE-918: Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect outbound model requests to an externally-controlled endpoint via a crafted inline flow configuration that overrides the HTTP Host header, resulting in disclosure of Google Cloud Vertex cloud service credentials and private signing keys.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-08-27T17:20:01.503Z",
  "pubdate": "2026-08-27T17:20:01.503Z",
  "executiveSummary": "A critical Server-Side Request Forgery (SSRF) vulnerability exists within the GitLab AI Gateway component, affecting versions 18.10 through 19.2.2. The flaw allows an authenticated user with access to the Duo Agent Platform to manipulate outbound model requests by overriding the HTTP Host header through a crafted inline flow configuration. This architectural weakness enables an attacker to redirect traffic to an arbitrary, externally-controlled endpoint. Successful exploitation results in the unauthorized disclosure of sensitive infrastructure secrets, specifically Google Cloud Vertex cloud service credentials and private signing keys. The vulnerability represents a significant risk to environment integrity, as it facilitates the exfiltration of high-privilege administrative tokens. Exploitation requires authenticated access to the GitLab Duo Agent Platform, after which the attacker can bypass internal security controls governing external communication. Remediation involves immediate patching to the latest secure versions to prevent potential credential theft and subsequent unauthorized access to cloud-based resources.",
  "technicalDetails": "The vulnerability resides within the request routing logic of the GitLab AI Gateway, specifically in how the component handles outbound model request configurations. The root cause is an improper validation of user-supplied input within the inline flow configuration, which allows for the injection or manipulation of the HTTP Host header. In a standard operation, the AI Gateway authenticates to Google Cloud Vertex services using predefined credentials; however, the lack of strict transport layer controls allows the Host header to be overridden.\nThe attack flow initiates when an authenticated user, possessing Duo Agent Platform access, submits a specially crafted payload within the inline flow configuration parameters. By manipulating the configuration, the attacker forces the underlying HTTP client to redirect the request to an attacker-controlled server instead of the legitimate Google Cloud API endpoints. Because the service performs this request using its internal execution context, it transmits existing environment-bound authentication headers and cryptographic signing keys to the rogue endpoint.\nThe exploitation process follows these technical steps: First, the attacker identifies a configuration vector that permits the modification of outgoing request headers. Second, the attacker crafts an inline flow object that forces a host redirection, effectively turning the AI Gateway into a proxy for the attacker. Third, when the Gateway attempts to fulfill the AI model request, it unknowingly leaks Google Cloud Vertex credentials and private signing keys to the attacker's listener as part of the standard authentication handshake or subsequent requests. The gateway effectively tunnels internal secrets to an external actor under the guise of an outbound model query.\nThis vulnerability affects GitLab AI Gateway versions: 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2. The impact is severe, as it facilitates the full compromise of the service's cloud identity. Post-exploitation, the acquired credentials and keys permit the attacker to impersonate the GitLab service within the targeted Google Cloud environment, potentially leading to unauthorized data access, service configuration changes, or broader infrastructure compromise. The vulnerability demonstrates a failure in secure request processing where the configuration layer is not sufficiently isolated from the transmission layer."
}
CVE-2026-75871: GitLab AI Gateway SSRF Vulnerability (HIGH Severity, CVSS: 8.2) - Sceawere