logo

CVE-2026-1868: Critical GitLab Gateway Flaw (CVSS 9.9) Allows RCE

ID: efd4af3f-200c-5945-90a7-f8420fb53472

STIX ID: report--efd4af3f-200c-5945-90a7-f8420fb53472

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-08

Date Updated: 2026-04-23

Author: Ddos

...
...

GitLab issued an urgent advisory for CVE-2026-1868 — an “Insecure Template expansion” flaw in the Duo Workflow Service of self-hosted GitLab AI Gateway (CVSS 9.9). The bug allows authenticated users supplying crafted Duo Agent Platform Flow definitions to cause a Denial of Service or gain code execution on the Gateway; affected versions include 18.1.6, 18.2.6, and 18.3.1 older than the fixed releases. GitLab released patched updates across release tracks and strongly urges immediate upgrades for self-managed installations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.