CVE-2026-1868Patch

MEDIUMCVSS 9.9 · CRITICAL

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in which AI Gateway was vulnerable to insecure template expansion of user supplied data via crafted Duo Agent Platform Flow definitions. This vulnerability could be used to cause Denial of Service or gain code execution on the Gateway. This has been fixed in versions 18.6.2, 18.7.1, and 18.8.1 of the GitLab AI Gateway.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 21 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 18 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 10d ago at 7 mentions (2026-02-08); latest day: 1
  • 21 total mentions across 11 days

Deep dive

Activity timeline21 mentions / 11d
02457Mentions · 2026-02-08: 7Mentions · 2026-02-09: 4Mentions · 2026-02-10: 2Mentions · 2026-02-16: 1Mentions · 2026-02-22: 1Mentions · 2026-03-15: 1Mentions · 2026-05-21: 1Mentions · 2026-07-25: 1Mentions · 2026-10-02: 1Mentions · 2026-10-03: 1Mentions · 2026-10-05: 1Active Exploitation · 2026-07-25: 1Patch / Workaround · 2026-02-08: 4Patch / Workaround · 2026-02-09: 4Patch / Workaround · 2026-02-10: 2Patch / Workaround · 2026-02-16: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-02-08: 7Technical Details · 2026-02-09: 4Technical Details · 2026-02-10: 2Technical Details · 2026-02-16: 1Technical Details · 2026-02-22: 1Technical Details · 2026-03-15: 1Technical Details · 2026-05-21: 1Technical Details · 2026-07-25: 102-0802-0902-1002-1602-2203-1505-2107-2510-0210-0310-05
Signal classification4 categories
Patch
1266.7%
Disclosure
422.2%
General
15.6%
Active Exploitation
15.6%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-02-087
Disclosure3Patch4
2026-02-094
Patch4
2026-02-102
Patch2
2026-02-161
Patch1
2026-02-221
General1
2026-03-151
Disclosure1
2026-05-211
Patch1
2026-07-251
Active Exploitation1
Full discourse20 posts
  • kokumօtօ@__kokumoto
    Patch

    GitLabで重大(Critical)な脆弱性が修正。CVE-2026-1868はCVSSスコア9.9のクロスサイトスクリプティング。GitLab AI Gatewayにおいて、細工されたDuo Agent Platform Flowを処理することで発現。 https://securityonline.info/cve-2026-1868-critical-gitlab-gateway-flaw-cvss-9-9-allows-rce/

    Post summary

    The post announces that GitLab AI Gateway’s critical XSS vulnerability (CVE-2026-1868, CVSS 9.9) has been fixed, with no PoC or exploitation details provided.

    040621.2K
    7.2K followersView on X
  • Slade 🛡️ LLM Hacker@llm_redteam

    CVE-2026-90970. CVSS 9.9. GitLab AI Gateway, fixed in 19.2.4 / 19.3.2 / 19.4.1. Any user with Duo Agent Platform access could craft a custom flow config that escapes the prompt template sandbox and runs arbitrary commands on the gateway. What makes this worth flagging: it's the same bug class as CVE-2026-1868, patched in February. Same component (Duo Workflow template engine), same CWE-1336 (template injection), same 9.9 score, same reporter base on HackerOne (invisiblemeerkat on this one). GitLab's advisory for 90970 doesn't even cross-reference the February CVE. That's two sandbox escapes in the same templating layer in eight months. A prompt template that renders user-controlled "flow configuration" into something executed server-side is not a one-off coding mistake, it's a design pattern that keeps producing RCE. [!] Affected: self-hosted AI Gateway, 18.1.6 through 19.1 (no fix exists below 19.2.4, so every release in that range is exposed with no workaround listed). [!] Not affected: http://GitLab.com, GitLab Dedicated, GitLab-hosted gateways. [!] Why the gateway matters: it holds JWT signing keys and brokers calls to your model provider. A command-exec escape there isn't contained to "AI feature broke," it's a foothold with credentials to pivot into your GitLab instance and your model provider account. CISA's exploitation assessment is "none" as of Oct 2, no public PoC. But with two near-identical escapes in one template engine, I'd bet on a third before year end unless GitLab rewrites the sandboxing model instead of patching the symptom. If you run a self-hosted gateway: check your version against 18.1.6-19.1 and update now, don't wait for a PoC to confirm urgency. #GitLab #PromptInjection #AIsecurity

    20021193
    1.3K followersView on X
  • ThreatCluster@threatcluster
    Patch

    GitLab patches critical CVE-2026-1868 (CVSS 9.9) in self-hosted AI Gateway, a template handling flaw that allows remote code execution. Admins should update affected instances immediately. #RCE https://threatcluster.io/cluster/critical-gitlab-gateway-flaw-cve-2026-1868-allows-rce-6204bc32

    Post summary

    GitLab has released a patch for the critical CVE‑2026‑1868 that enables remote code execution in its self‑hosted AI Gateway; administrators are urged to apply the update immediately.

    01022258
    79 followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    CVE-2026-1868: Critical GitLab Gateway Flaw (CVSS 9.9) Allows RCE https://securityonline.info/cve-2026-1868-critical-gitlab-gateway-flaw-cvss-9-9-allows-rce/

    Post summary

    The text announces a critical GitLab Gateway vulnerability (CVE-2026-1868) with a CVSS score of 9.9 that permits remote code execution, without providing a PoC, exploit code, or patch information.

    0001277
    73 followersView on X
  • Awais Khawar, PhD | 2x books | AI/Cloud Expert@awais_khawar

    Second, this is the second 9.9 in the same component this year. February brought CVE-2026-1868: same CWE-1336 template weakness, same crafted flow vector. When the same sandbox breaks twice in eight months, the sandbox is the design.

    1000034
    95 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-1868 - Critical DoS/RCE in GitLab AI Gateway. Insecure template expansion in Duo Workflow Service. CVSS 9.9. Update to 18.6.2, 18.7.1, or 18.8.1 immediately. #CVE #GitLab #InfoSec #infosecurity #git #DevSecOps #Devops More: https://www.valtersit.com/cve/CVE-2026-1868/

    Post summary

    The notice announces a critical DoS/RCE vulnerability in GitLab AI Gateway (CVE-2026-1868) and urges users to upgrade to the specified patch versions immediately.

    00010132
    904 followersView on X
  • Mikel@MikelEcheve
    General

    Migrating to self-hosted GitLab isn't the silver bullet anymore. CVE-2026-1868 (9.9/10) proved it. The vulnerability wasn't in the core, but in the "AI Gateway" module. 🤖🚫 Shoving AI into infrastructure is creating massive security holes. https://t.co/FiwFFHOy0t

    Post summary

    The tweet points out a high‑severity CVE‑2026‑1868 affecting GitLab’s AI Gateway module, warning that AI integration creates security holes, but it offers no details on patches, exploits, or active attacks.

    1000079
    223 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Web Services Stack (CVSS 9.8-9.9) Affected: jsonpath (npm); GitLab AI Gateway; Lighttpd Internet-facing risks dominate, driven by pre-auth and unauthenticated exploits across a JSON-path library, a gateway service, and a web server. CVE-2026-1868 (CVSS 9.9) GitLab AI Gateway Duo Workflow Service is affected by insecure template expansion of user-supplied Duo Agent Platform Flow definitions across AI Gateway versions 18.1.6 through 18.8.0, enabling potential DoS or code execution. CVE-2026-1615 (CVSS 9.8) All versions of jsonpath are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. CVE-2026-22903 (CVSS 9.8) A modified lighttpd server can be triggered by an unauthenticated remote attacker sending a crafted HTTP request with an overly long SESSIONID cookie, causing a stack buffer overflow that can crash the service and may enable remote code execution. CVE-2026-22904 (CVSS 9.8) Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated attacker to send oversized cookie values that trigger a stack buffer overflow, leading to denial of service and potential remote code execution. 🛠️ Action • Patch/upgrade GitLab AI Gateway to 18.6.2, 18.7.1, or 18.8.1 (per advisory) and apply vendor updates for impacted components when available • Prioritize internet-facing instances and edge deployments for rapid remediation • For jsonpath (CVE-2026-1615) with no fix yet, apply mitigations such as avoiding evaluation of untrusted JSONPath expressions or sandboxing input; monitor for patches • Add detections for exploitation patterns: suspicious JSONPath input attempts and anomalous script execution in eval paths; monitor relevant logs • Hunt for indicators around the affected services during disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces several high‑CVSS vulnerabilities and supplies vendor patches, mitigations, and monitoring guidance.

    00010105
    64 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    📝 𝐂𝐕𝐄-𝟐𝟎𝟐𝟔-𝟏𝟖𝟔𝟖: 𝐂𝐫𝐢𝐭𝐢𝐜𝐚𝐥 𝐆𝐢𝐭𝐋𝐚𝐛 𝐆𝐚𝐭𝐞𝐰𝐚𝐲 𝐅𝐥𝐚𝐰 (𝐂𝐕𝐒𝐒 𝟗.𝟗) 𝐀𝐥𝐥𝐨𝐰𝐬 𝐑𝐂𝐄 • A critical vulnerability (CVE-2026-1868) exists in GitLab's self-hosted AI Gateway, rated with a CVSS score of 9.9. • The flaw, an insecure template expansion issue, enables authenticated attackers to cause denial of service or remote code execution. • Administrators of affected GitLab AI Gateway versions must upgrade immediately to patched releases like 18.6.2, 18.7.1, or 18.8.1. A critical vulnerability in GitLab's self-hosted AI Gateway allows authenticated attackers to perform remote code execution or denial of service, requiring urgent updates for affected versions.

    Post summary

    GitLab’s self‑hosted AI Gateway suffers a critical insecure template expansion flaw that allows authenticated RCE or DoS. Administrators are urged to upgrade immediately to the patched releases 18.6.2, 18.7.1, or 18.8.1.

    00010111
    64 followersView on X
  • Cyb3rVolt3x@AndraxPentester

    Scope note for triage: CVE-2026-90970 only hits self-hosted AI Gateway — http://GitLab.com, Dedicated, and GitLab-hosted gateways are already patched. Root cause is CWE-1336 in the custom-flow prompt template: Duo Agent Platform access + crafted flow config escapes the template sandbox to RCE on the gateway (CVSS 9.9, scope changed). Patch to 19.2.4 / 19.3.2 / 19.4.1 and inventory who actually runs self-hosted-v*.*-ee images before paging the whole org. Same template-engine class as February's CVE-2026-1868.

    0000083
    48 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited GitLab's Jupyter notebook diff rendering to execute commands as the 'git' user without admin privileges. CVE-2026-1868 demonstrates how AI infrastructure components create new attack surfaces that bypass traditional access controls. #CloudSecurity #ZeroDay 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/gitlab-rce-vulnerability-cve-2026-1868

    Post summary

    The post reports that attackers have exploited a GitLab Jupyter notebook rendering flaw (CVE‑2026‑1868) to run commands as the git user, indicating active use in the wild, but it provides no PoC, exploit code, or patch information.

    0000050
    1.9K followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #AIGateway CVE-2026-1868: Critical GitLab Gateway Flaw (CVSS 9.9) Allows RCE https://securityonline.info/cve-2026-1868-critical-gitlab-gateway-flaw-cvss-9-9-allows-rce/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces the GitLab Gateway CVE-2026-1868 with a CVSS score of 9.9 and an RCE impact, linking to a detailed security article for further information.

    0000092
    1.5K followersView on X
  • RagingCISO@CisoRaging77913
    Patch

    CVE-2026-1868: GitLab CVSS 9.9—RCE on the platform holding your code, secrets, and pipelines. Unpatched instance? That's a vault in the lobby with "code inside" on a post-it. Patch in days, not weeks. Or drop "DevSecOps" from the slides—you're not doing it.

    Post summary

    The tweet focuses on the critical RCE vulnerability CVE-2026-1868 in GitLab, emphasizing the urgency of applying the patch within days.

    0000045
    3 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Web Services Stack (CVSS 9.8-9.9) Affected: jsonpath (npm); GitLab AI Gateway; Lighttpd Internet-facing risks dominate, driven by pre-auth and unauthenticated exploits across a JSON-path library, a gateway service, and a web server. CVE-2026-1868 (CVSS 9.9) GitLab AI Gateway Duo Workflow Service is affected by insecure template expansion of user-supplied Duo Agent Platform Flow definitions across AI Gateway versions 18.1.6 through 18.8.0, enabling potential DoS or code execution. CVE-2026-1615 (CVSS 9.8) All versions of jsonpath are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. CVE-2026-22903 (CVSS 9.8) A modified lighttpd server can be triggered by an unauthenticated remote attacker sending a crafted HTTP request with an overly long SESSIONID cookie, causing a stack buffer overflow that can crash the service and may enable remote code execution. CVE-2026-22904 (CVSS 9.8) Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated attacker to send oversized cookie values that trigger a stack buffer overflow, leading to denial of service and potential remote code execution. 🛠️ Action • Patch/upgrade GitLab AI Gateway to 18.6.2, 18.7.1, or 18.8.1 (per advisory) and apply vendor updates for impacted components when available • Prioritize internet-facing instances and edge deployments for rapid remediation • For jsonpath (CVE-2026-1615) with no fix yet, apply mitigations such as avoiding evaluation of untrusted JSONPath expressions or sandboxing input; monitor for patches • Add detections for exploitation patterns: suspicious JSONPath input attempts and anomalous script execution in eval paths; monitor relevant logs • Hunt for indicators around the affected services during disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces three high‑severity CVEs affecting GitLab AI Gateway, jsonpath, and lighttpd, provides detailed technical information, and delivers patch upgrades and mitigation guidance.

    0000080
    64 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-1868: CRITICAL] Vulnerability in GitLab AI Gateway's Duo Workflow Service component fixed in versions 18.6.2, 18.7.1, and 18.8.1, preventing potential Denial of Service attacks and code execution.#cve,CVE-2026-1868,#cybersecurity https://cvefind.com/CVE-2026-1868

    Post summary

    CVE‑2026‑1868, a critical GitLab AI Gateway vulnerability allowing potential DoS and code execution, has been fixed in versions 18.6.2, 18.7.1, and 18.8.1.

    0000096
    583 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: GitLab AI Gateway flaw (CVE-2026-1868) lets attackers run code or cause DoS via Duo Workflow Service. Affects versions 18.1.6 – 18.8.0. Patch ASAP! 🔒 https://radar.offseq.com/threat/cve-2026-1868-cwe-1336-improper-neutralization-of--f5bf4abe #OffSeq #GitLab #Vulner... https://t.co/wOtWyjJ5Vx

    Post summary

    GitLab AI Gateway flaw (CVE-2026-1868) allows code execution or DoS via Duo Workflow Service; affected versions 18.1.6–18.8.0 and urgent patching is recommended.

    0000065
    268 followersView on X
  • The Hacker Wire@TheHackerWire
    Patch

    🔴 CVE-2026-1868 - Critical GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and... https://www.thehackerwire.com/vulnerability/CVE-2026-1868/ https://t.co/YrPMev8D8Z

    Post summary

    GitLab has issued a patch for CVE‑2026‑1868 affecting several AI Gateway versions, as noted in the linked advisory.

    0000083
    112 followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    CVE-2026-1868: Critical GitLab Gateway Flaw (CVSS 9.9) Allows RCE https://securityonline.info/cve-2026-1868-critical-gitlab-gateway-flaw-cvss-9-9-allows-rce/

    Post summary

    The text announces CVE-2026-1868, a critical GitLab Gateway flaw with a CVSS score of 9.9 that allows remote code execution, but it does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000068
    299 followersView on X
  • Explain IT Again@xplain_it_again
    Patch

    Critical GitLab Gateway Flaw Exploits Remote Code Execution Vulnerability - Patch ASAP! #gitlab #cybersecurity #vulnerability #remoteexecution https://explainitagain.wixsite.com/explain-it-again/post/cve-2026-1868-critical-gitlab-gateway-flaw-exploits-remote-code-execution-vulnerability

    Post summary

    The post announces a critical GitLab RCE flaw and urges immediate patching, but lacks detailed technical info, exploit code, or evidence of active exploitation.

    0000061
    1 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🔍 𝐋𝐚𝐭𝐞𝐬𝐭 𝐂𝐕𝐄 𝐛𝐫𝐞𝐚𝐤𝐝𝐨𝐰𝐧 𝐚𝐯𝐚𝐢𝐥𝐚𝐛𝐥𝐞 𝐧𝐨𝐰! CVE-2026-1868 lets attackers execute code via GitLab’s AI Gateway. Find out how to protect your DevSecOps pipeline from this critical flaw. 👉 Dive into the full analysis → https://www.purple-ops.io/cybersecurity-threat-intelligence-blog/gitlab-ai-gateway-rce-2/ Stay safe, and let us know your thoughts!

    Post summary

    The post announces CVE‑2026‑1868, a code‑execution flaw in GitLab’s AI Gateway, and directs readers to a blog for protection guidance, but does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    0000061
    64 followersView on X

Explore more