
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75871 is a Server-Side Request Forgery (SSRF) vulnerability in the GitLab AI Gateway component that allows an authenticated user with Duo Agent Platform access to redirect outbound model requests to an attacker-controlled endpoint by crafting an inline flow configuration that overrides the HTTP Host header. This can result in the disclosure of Google Cloud Vertex cloud service credentials and private signing keys. Affected versions include GitLab AI Gateway 18.10 through 19.0.12, 19.1 through 19.1.7, and 19.2 through 19.2.2. The vulnerability was published on August 27, 2026. The CVSS v3.1 base score is 9.6 (Critical) per NVD, while the GitHub Advisory and ENISA score it at 8.2 (High) (GitHub Advisory).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and stems from insufficient validation of inline flow configurations within the GitLab AI Gateway's Duo Agent Platform. An authenticated attacker can craft a malicious flow configuration that overrides the HTTP Host header in outbound model requests, redirecting those requests to an externally-controlled endpoint. This Host header injection enables the attacker's server to receive requests intended for Google Cloud Vertex AI services, including authentication tokens and private signing keys embedded in those requests. The vulnerability was reported via HackerOne (report #3945100) and tracked internally at GitLab (GitHub Advisory).
Successful exploitation results in high confidentiality and integrity impact with no availability impact. An attacker can obtain Google Cloud Vertex cloud service credentials and private signing keys, which could be leveraged for unauthorized access to cloud resources, lateral movement within the victim's cloud environment, or further supply chain compromise. The scope change (S:C) in the CVSS vector indicates that the impact extends beyond the AI Gateway component itself to the broader cloud infrastructure (GitHub Advisory).
No public proof-of-concept exploit code has been observed, and there is no evidence of in-the-wild exploitation at this time. The NVD SSVC assessment notes exploitation status as "poc" but no confirmed public PoC has been identified. The EPSS score is approximately 0.19%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication and Duo Agent Platform access, which limits the attacker pool but does not eliminate risk from insider threats or compromised accounts (GitHub Advisory).
Host: attacker.example.com).GitLab has released patched versions of the AI Gateway: upgrade to 19.0.13 or later (for 18.10–19.0.x deployments), 19.1.8 or later (for 19.1.x deployments), or 19.2.3 or later (for 19.2.x deployments). As interim mitigations, restrict Duo Agent Platform access to only authorized and trusted users, implement network-level egress controls to prevent the AI Gateway from establishing connections to untrusted external endpoints, and monitor outbound connections from the AI Gateway for anomalous activity. If immediate patching is not possible, consider disabling the Duo Agent Platform feature until the patch can be applied (GitHub Advisory).
The vulnerability was disclosed by GitLab on August 27, 2026, and reported through HackerOne (report #3945100). Limited public commentary has been observed, with brief mentions on social media platforms such as Bluesky. No significant vendor statements beyond the advisory or notable independent researcher analysis has been published at this time (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."