CVE-2026-75871:
GitLab 취약성 분석 및 완화
개요
CVE-2026-75871 is a Server-Side Request Forgery (SSRF) vulnerability in the GitLab AI Gateway component that allows an authenticated user with Duo Agent Platform access to redirect outbound model requests to an attacker-controlled endpoint by crafting an inline flow configuration that overrides the HTTP Host header. This can result in the disclosure of Google Cloud Vertex cloud service credentials and private signing keys. Affected versions include GitLab AI Gateway 18.10 through 19.0.12, 19.1 through 19.1.7, and 19.2 through 19.2.2. The vulnerability was published on August 27, 2026. The CVSS v3.1 base score is 9.6 (Critical) per NVD, while the GitHub Advisory and ENISA score it at 8.2 (High) (GitHub Advisory).
기술적 세부 사항
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and stems from insufficient validation of inline flow configurations within the GitLab AI Gateway's Duo Agent Platform. An authenticated attacker can craft a malicious flow configuration that overrides the HTTP Host header in outbound model requests, redirecting those requests to an externally-controlled endpoint. This Host header injection enables the attacker's server to receive requests intended for Google Cloud Vertex AI services, including authentication tokens and private signing keys embedded in those requests. The vulnerability was reported via HackerOne (report #3945100) and tracked internally at GitLab (GitHub Advisory).
영향
Successful exploitation results in high confidentiality and integrity impact with no availability impact. An attacker can obtain Google Cloud Vertex cloud service credentials and private signing keys, which could be leveraged for unauthorized access to cloud resources, lateral movement within the victim's cloud environment, or further supply chain compromise. The scope change (S:C) in the CVSS vector indicates that the impact extends beyond the AI Gateway component itself to the broader cloud infrastructure (GitHub Advisory).
악용 가능성
No public proof-of-concept exploit code has been observed, and there is no evidence of in-the-wild exploitation at this time. The NVD SSVC assessment notes exploitation status as "poc" but no confirmed public PoC has been identified. The EPSS score is approximately 0.19%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication and Duo Agent Platform access, which limits the attacker pool but does not eliminate risk from insider threats or compromised accounts (GitHub Advisory).
착취 단계
- Reconnaissance: Identify a GitLab instance running AI Gateway versions 18.10–19.0.12, 19.1–19.1.7, or 19.2–19.2.2 with the Duo Agent Platform feature enabled.
- Authentication: Obtain valid credentials for an account with Duo Agent Platform access (e.g., through phishing, credential stuffing, or insider access).
- Craft malicious flow configuration: Create an inline flow configuration payload that overrides the HTTP Host header in outbound model requests, pointing it to an attacker-controlled server (e.g.,
Host: attacker.example.com). - Submit the crafted configuration: Submit the malicious inline flow configuration through the Duo Agent Platform interface, triggering the AI Gateway to make outbound requests to the attacker-controlled endpoint.
- Capture credentials: On the attacker-controlled server, capture the incoming HTTP requests, which will contain Google Cloud Vertex cloud service credentials and private signing keys embedded in the redirected traffic.
- Leverage captured credentials: Use the obtained Google Cloud Vertex credentials and signing keys to authenticate to cloud services, access sensitive data, or pivot to other cloud resources (GitHub Advisory).
타협의 징후
- Network: Outbound HTTP/HTTPS requests from the AI Gateway to unexpected or external IP addresses/domains not associated with Google Cloud Vertex AI endpoints; anomalous DNS queries from the AI Gateway host to unknown domains.
- Logs: AI Gateway access logs showing model requests with unusual or modified Host headers; requests to Duo Agent Platform endpoints originating from unfamiliar user accounts or at unusual times.
- Cloud: Unexpected API calls to Google Cloud Vertex AI services from unfamiliar source IPs or service accounts; alerts from Google Cloud IAM for credential usage from anomalous locations.
- Process/Application: Unusual inline flow configurations submitted to the Duo Agent Platform, particularly those containing external hostnames or IP addresses in Host header fields (GitHub Advisory).
완화 및 해결 방법
GitLab has released patched versions of the AI Gateway: upgrade to 19.0.13 or later (for 18.10–19.0.x deployments), 19.1.8 or later (for 19.1.x deployments), or 19.2.3 or later (for 19.2.x deployments). As interim mitigations, restrict Duo Agent Platform access to only authorized and trusted users, implement network-level egress controls to prevent the AI Gateway from establishing connections to untrusted external endpoints, and monitor outbound connections from the AI Gateway for anomalous activity. If immediate patching is not possible, consider disabling the Duo Agent Platform feature until the patch can be applied (GitHub Advisory).
커뮤니티 반응
The vulnerability was disclosed by GitLab on August 27, 2026, and reported through HackerOne (report #3945100). Limited public commentary has been observed, with brief mentions on social media platforms such as Bluesky. No significant vendor statements beyond the advisory or notable independent researcher analysis has been published at this time (GitHub Advisory).
추가 자료
근원: 이 보고서는 AI를 사용하여 생성되었습니다.
관련 GitLab 취약점:
무료 취약성 평가
클라우드 보안 태세를 벤치마킹합니다
9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.
추가 Wiz 리소스
맞춤형 데모 받기
맞춤형 데모 신청하기
"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."