
🚨 Critical CVEs Today: Web Services Stack (CVSS 9.8-9.9) Affected: jsonpath (npm); GitLab AI Gateway; Lighttpd Internet-facing risks dominate, driven by pre-auth and unauthenticated exploits across a JSON-path library, a gateway service, and a web server. CVE-2026-1868 (CVSS 9.9) GitLab AI Gateway Duo Workflow Service is affected by insecure template expansion of user-supplied Duo Agent Platform Flow definitions across AI Gateway versions 18.1.6 through 18.8.0, enabling potential DoS or code execution. CVE-2026-1615 (CVSS 9.8) All versions of jsonpath are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. CVE-2026-22903 (CVSS 9.8) A modified lighttpd server can be triggered by an unauthenticated remote attacker sending a crafted HTTP request with an overly long SESSIONID cookie, causing a stack buffer overflow that can crash the service and may enable remote code execution. CVE-2026-22904 (CVSS 9.8) Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated attacker to send oversized cookie values that trigger a stack buffer overflow, leading to denial of service and potential remote code execution. 🛠️ Action • Patch/upgrade GitLab AI Gateway to 18.6.2, 18.7.1, or 18.8.1 (per advisory) and apply vendor updates for impacted components when available • Prioritize internet-facing instances and edge deployments for rapid remediation • For jsonpath (CVE-2026-1615) with no fix yet, apply mitigations such as avoiding evaluation of untrusted JSONPath expressions or sandboxing input; monitor for patches • Add detections for exploitation patterns: suspicious JSONPath input attempts and anomalous script execution in eval paths; monitor relevant logs • Hunt for indicators around the affected services during disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion
Post summary
The post announces critical CVEs, details technical aspects, and provides patch and mitigation guidance without evidence of PoC or active exploitation.





