CVE-2026-75871
GitLab vulnerability analysis and mitigation

Overview

CVE-2026-75871 is a Server-Side Request Forgery (SSRF) vulnerability in the GitLab AI Gateway component that allows an authenticated user with Duo Agent Platform access to redirect outbound model requests to an attacker-controlled endpoint by crafting an inline flow configuration that overrides the HTTP Host header. This can result in the disclosure of Google Cloud Vertex cloud service credentials and private signing keys. Affected versions include GitLab AI Gateway 18.10 through 19.0.12, 19.1 through 19.1.7, and 19.2 through 19.2.2. The vulnerability was published on August 27, 2026. The CVSS v3.1 base score is 9.6 (Critical) per NVD, while the GitHub Advisory and ENISA score it at 8.2 (High) (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and stems from insufficient validation of inline flow configurations within the GitLab AI Gateway's Duo Agent Platform. An authenticated attacker can craft a malicious flow configuration that overrides the HTTP Host header in outbound model requests, redirecting those requests to an externally-controlled endpoint. This Host header injection enables the attacker's server to receive requests intended for Google Cloud Vertex AI services, including authentication tokens and private signing keys embedded in those requests. The vulnerability was reported via HackerOne (report #3945100) and tracked internally at GitLab (GitHub Advisory).

Impact

Successful exploitation results in high confidentiality and integrity impact with no availability impact. An attacker can obtain Google Cloud Vertex cloud service credentials and private signing keys, which could be leveraged for unauthorized access to cloud resources, lateral movement within the victim's cloud environment, or further supply chain compromise. The scope change (S:C) in the CVSS vector indicates that the impact extends beyond the AI Gateway component itself to the broader cloud infrastructure (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code has been observed, and there is no evidence of in-the-wild exploitation at this time. The NVD SSVC assessment notes exploitation status as "poc" but no confirmed public PoC has been identified. The EPSS score is approximately 0.19%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication and Duo Agent Platform access, which limits the attacker pool but does not eliminate risk from insider threats or compromised accounts (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a GitLab instance running AI Gateway versions 18.10–19.0.12, 19.1–19.1.7, or 19.2–19.2.2 with the Duo Agent Platform feature enabled.
  2. Authentication: Obtain valid credentials for an account with Duo Agent Platform access (e.g., through phishing, credential stuffing, or insider access).
  3. Craft malicious flow configuration: Create an inline flow configuration payload that overrides the HTTP Host header in outbound model requests, pointing it to an attacker-controlled server (e.g., Host: attacker.example.com).
  4. Submit the crafted configuration: Submit the malicious inline flow configuration through the Duo Agent Platform interface, triggering the AI Gateway to make outbound requests to the attacker-controlled endpoint.
  5. Capture credentials: On the attacker-controlled server, capture the incoming HTTP requests, which will contain Google Cloud Vertex cloud service credentials and private signing keys embedded in the redirected traffic.
  6. Leverage captured credentials: Use the obtained Google Cloud Vertex credentials and signing keys to authenticate to cloud services, access sensitive data, or pivot to other cloud resources (GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS requests from the AI Gateway to unexpected or external IP addresses/domains not associated with Google Cloud Vertex AI endpoints; anomalous DNS queries from the AI Gateway host to unknown domains.
  • Logs: AI Gateway access logs showing model requests with unusual or modified Host headers; requests to Duo Agent Platform endpoints originating from unfamiliar user accounts or at unusual times.
  • Cloud: Unexpected API calls to Google Cloud Vertex AI services from unfamiliar source IPs or service accounts; alerts from Google Cloud IAM for credential usage from anomalous locations.
  • Process/Application: Unusual inline flow configurations submitted to the Duo Agent Platform, particularly those containing external hostnames or IP addresses in Host header fields (GitHub Advisory).

Mitigation and workarounds

GitLab has released patched versions of the AI Gateway: upgrade to 19.0.13 or later (for 18.10–19.0.x deployments), 19.1.8 or later (for 19.1.x deployments), or 19.2.3 or later (for 19.2.x deployments). As interim mitigations, restrict Duo Agent Platform access to only authorized and trusted users, implement network-level egress controls to prevent the AI Gateway from establishing connections to untrusted external endpoints, and monitor outbound connections from the AI Gateway for anomalous activity. If immediate patching is not possible, consider disabling the Duo Agent Platform feature until the patch can be applied (GitHub Advisory).

Community reactions

The vulnerability was disclosed by GitLab on August 27, 2026, and reported through HackerOne (report #3945100). Limited public commentary has been observed, with brief mentions on social media platforms such as Bluesky. No significant vendor statements beyond the advisory or notable independent researcher analysis has been published at this time (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-85706CRITICAL10
  • GitLab logoGitLab
  • gitlab
YesYesSep 12, 2026
CVE-2026-87719CRITICAL9.9
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 12, 2026
CVE-2026-75871CRITICAL9.6
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 27, 2026
CVE-2026-77801MEDIUM6.5
  • GitLab logoGitLab
  • gitlab-cng-19.3
NoYesAug 26, 2026
CVE-2026-7487LOW3.5
  • GitLab logoGitLab
  • gitlab-rails-19.3
NoYesAug 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management