CVE-2026-19889

8.2

GitLab · AI Gateway

A Server-Side Request Forgery vulnerability in the GitLab AI Gateway allows authenticated users with Duo Agent Platform access to redirect model requests and disclose cloud service credentials.

Executive summary

An authenticated Server-Side Request Forgery vulnerability in GitLab AI Gateway allows attackers to exfiltrate sensitive cloud service credentials, necessitating an immediate software update.

Vulnerability

This vulnerability is a Server-Side Request Forgery (CWE-918) flaw. It requires an authenticated user with Duo Agent Platform access to manipulate model metadata, forcing the gateway to send requests to arbitrary, externally controlled endpoints.

Business impact

The exploitation of this vulnerability results in the disclosure of critical Google Vertex AI or AWS Bedrock cloud service credentials. Given the CVSS score of 8.2, this represents a high risk to organizational security, as compromised credentials can lead to unauthorized access to cloud infrastructure, potential data exfiltration, and significant financial or reputational damage.

Remediation

Immediate Action: Upgrade the GitLab AI Gateway to version 19.0.12, 19.1.7, 19.2.2, 19.3.0, or any newer stable release provided by GitLab.

Proactive Monitoring: Audit access logs for the Duo Agent Platform to identify unusual outbound requests or metadata configurations that deviate from established operational baselines.

Compensating Controls: Implement strict egress filtering on the AI Gateway server to prevent unauthorized communication with external endpoints until the patch can be applied.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists via the reference provided in the HackerOne report.

Analyst recommendation

The risk posed by the potential exposure of cloud service credentials is severe and requires immediate attention. Administrators must prioritize updating the GitLab AI Gateway to the specified patched versions to neutralize the SSRF vector. Failure to remediate this vulnerability leaves the environment susceptible to unauthorized cloud service access and potential long-term infrastructure compromise.

More GitLab CVEs

Sources

Originally found and disclosed by Thanks [kyyblin](https://hackerone.com/kyyblin) for reporting this vulnerability through our HackerOne bug bounty progra, per the CVE Program record.