External risk intelligence

GitLab AI Gateway Credential Disclosure Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-75871

The vulnerability affects the GitLab AI Gateway, which acts as an intermediary or edge service for processing AI model requests. Such components are typically deployed as network-accessible services to facilitate communication between internal applications and external model providers, making them commonly reachable in modern development environments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in GitLab's AI Gateway component that could allow an authenticated user to redirect model requests. This could lead to the exposure of sensitive cloud service credentials and private keys.

  • Issue: Redirected AI requests could expose cloud credentials.
  • Why remember: Affects AI gateway, a common intermediary service.
  • Executive takeaway: Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker with authenticated access to the GitLab AI Gateway could manipulate its configuration to send model requests to a malicious endpoint. This manipulation is achieved by crafting an inline flow configuration that overrides the HTTP Host header, potentially exposing sensitive cloud credentials.

  • Authenticated user with Duo Agent access.
  • Crafted inline flow configuration.
  • Disclosure of cloud credentials and keys.

Live Threat

Current exploitation, exposure, and threat context

An authenticated user with Duo Agent Platform access could redirect model requests to an externally-controlled endpoint, potentially exposing Google Cloud Vertex cloud service credentials and private signing keys. This could occur when the GitLab AI Gateway processes a crafted inline flow configuration that manipulates the HTTP Host header.

  • Cloud service credentials
  • Redirected model requests
  • Key compromise

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability within GitLab's AI Gateway necessitates coordinated action from platform or infrastructure teams responsible for GitLab deployments, alongside the specific application owners utilizing the AI Gateway. The immediate priority is to identify all instances of the affected GitLab versions, assess their exposure, confirm business criticality, and locate the accountable owner before planning remediation.

  • Platform teams should own the issue.
  • Verify AI Gateway external reachability and critical assets.
  • Plan targeted remediation during a maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the GitLab AI Gateway?

The AI Gateway is a specialized component within GitLab designed to handle communication between internal platform services and external artificial intelligence model providers. It acts as an intermediary, processing requests for AI features like Duo and managing the necessary integrations with cloud-based model services.

How does CWE-918 apply to CVE-2026-75871?

This CVE is categorized as CWE-918, which stands for Server-Side Request Forgery. In this context, it means the software can be tricked into sending data to a location of an attacker's choosing. By manipulating the configuration, an authenticated user forces the gateway to send requests to an unintended, external destination, which leads to the disclosure of sensitive cloud keys.

Do I need to be an administrator to trigger this bug?

You do not need administrative rights, but you must have authenticated access specifically to the Duo Agent Platform. The bug is triggered when a user provides a specially crafted inline flow configuration that overrides the HTTP Host header. Standard, legitimate model requests that do not include this specific malicious configuration manipulation will not trigger the vulnerability.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal indicates that your risk level is likely elevated if your AI Gateway is reachable over the network. Because this component serves as an edge service facilitating communication between your internal environment and external providers, it is often designed to be network-accessible, which increases the likelihood of exposure.

When should I prioritize patching for CVE-2026-75871?

You should prioritize this as a critical task if you are running versions of GitLab within the affected ranges. Begin by identifying all instances of the AI Gateway in your environment. Once you have located these assets and confirmed who is responsible for their maintenance, coordinate with your infrastructure teams to schedule an update to a secure version.

References