CVE-2026-1868: Critical GitLab Gateway Flaw (CVSS 9.9) Allows RCE
ID: efd4af3f-200c-5945-90a7-f8420fb53472
STIX ID: report--efd4af3f-200c-5945-90a7-f8420fb53472
Feed Name: securityonline.info
GitLab issued an urgent advisory for CVE-2026-1868 — an “Insecure Template expansion” flaw in the Duo Workflow Service of self-hosted GitLab AI Gateway (CVSS 9.9). The bug allows authenticated users supplying crafted Duo Agent Platform Flow definitions to cause a Denial of Service or gain code execution on the Gateway; affected versions include 18.1.6, 18.2.6, and 18.3.1 older than the fixed releases. GitLab released patched updates across release tracks and strongly urges immediate upgrades for self-managed installations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
