GitLab security patch release for CVE-2026-90970
Security Patch Release
Summary
Hide ▲
Show ▼
GitLab released 19.2.4, 19.3.2, and 19.4.1 to fix CVE-2026-90970 in GitLab Self-Hosted AI Gateway, closing a critical command-execution path for vulnerable self-managed deployments. The patch applies to customers running their own AI Gateway instances through GitLab Duo Self-Hosted. GitLab said GitLab-hosted AI Gateway users are already protected and do not need to take action.
Related Happenings
GitLab Self-Hosted AI Gateway immediate update advisory (CVE-2026-90970)
Advisory/Mitigation
H score41
First: 02.10.2026 19:20
Last: 02.10.2026 19:20
Sources 1
How related:
GitLab strongly recommends that those customers update immediately.
About this happening:
GitLab issued immediate update guidance for GitLab Self-Managed customers running Self-Hosted AI Gateway after fixing CVE-2026-90970, a flaw that could allow arb...
GitLab Self-Hosted AI Gateway immediate update advisory (CVE-2026-90970)
Advisory/MitigationHow related: GitLab strongly recommends that those customers update immediately.
About this happening: GitLab issued immediate update guidance for GitLab Self-Managed customers running Self-Hosted AI Gateway after fixing CVE-2026-90970, a flaw that could allow arb...
Red Heron Gitea CVE-2026-60004 exploitation wave
Exploitation Wave
H score22
First: 14.09.2026 19:56
Last: 14.09.2026 19:56
Sources 1
About this happening:
An active CVE-2026-60004 exploitation wave is targeting Gitea instances across seven countries, converting public proof-of-concept code into an automated scanning fram...
Red Heron Gitea CVE-2026-60004 exploitation wave
Exploitation WaveAbout this happening: An active CVE-2026-60004 exploitation wave is targeting Gitea instances across seven countries, converting public proof-of-concept code into an automated scanning fram...
GitLab CE/EE security update for CVE-2026-85706
Security Patch Release
H score44
First: 14.09.2026 10:06
Last: 14.09.2026 10:06
Sources 1
About this happening:
GitLab released CE/EE fixes for CVE-2026-85706, and users were urged to patch immediately to close a repository commits API flaw that can expose credentials and se...
GitLab CE/EE security update for CVE-2026-85706
Security Patch ReleaseAbout this happening: GitLab released CE/EE fixes for CVE-2026-85706, and users were urged to patch immediately to close a repository commits API flaw that can expose credentials and se...
CISA KEV listing and BOD 26-04 remediation deadline for GitLab CVE-2026-85706
Public Sector Action
H score36
First: 14.09.2026 10:06
Last: 14.09.2026 10:06
Sources 1
About this happening:
CISA added CVE-2026-85706 to its actively exploited catalog and gave federal agencies three days to secure affected systems under BOD 26-04. The move turns the...
CISA KEV listing and BOD 26-04 remediation deadline for GitLab CVE-2026-85706
Public Sector ActionAbout this happening: CISA added CVE-2026-85706 to its actively exploited catalog and gave federal agencies three days to secure affected systems under BOD 26-04. The move turns the...
GitLab CE/EE security patch release (CVE-2023-2825, CVE-2026-87719)
Security Patch Release
H score45
First: 11.09.2026 14:15
Last: 11.09.2026 14:15
Sources 1
About this happening:
GitLab released fixes for CVE-2023-2825 and CVE-2026-87719 in GitLab Community Edition (CE) and Enterprise Edition (EE), requiring self-managed installations...
GitLab CE/EE security patch release (CVE-2023-2825, CVE-2026-87719)
Security Patch ReleaseAbout this happening: GitLab released fixes for CVE-2023-2825 and CVE-2026-87719 in GitLab Community Edition (CE) and Enterprise Edition (EE), requiring self-managed installations...
Timeline
-
02.10.2026 19:20 3 articles · 1h ago
GitLab releases 19.2.4, 19.3.2, and 19.4.1 for GitLab Self-Hosted AI Gateway
Mitigation Patch UpdateGitLab released versions 19.2.4, 19.3.2, and 19.4.1 to fix CVE-2026-90970 in GitLab Self-Hosted AI Gateway after warning that an authenticated user with Duo Agent Platform access could escape the prompt template sandbox via a specially crafted flow configuration and execute arbitrary commands on unpatched self-managed instances. GitLab said GitLab-hosted AI Gateway users are already protected and urged GitLab Self-Managed customers with self-hosted AI Gateway installations to upgrade immediately.
Show sources
- GitLab warns of critical RCE vulnerability in AI Gateway service — www.bleepingcomputer.com — 02.10.2026 19:20
- GitLab warns of critical RCE vulnerability in AI Gateway service — www.bleepingcomputer.com — 02.10.2026 19:20
- GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers — thehackernews.com — 02.10.2026 20:33