GitLab Self-Hosted AI Gateway immediate update advisory (CVE-2026-90970)
Advisory/Mitigation
Summary
Hide ▲
Show ▼
GitLab issued immediate update guidance for GitLab Self-Managed customers running Self-Hosted AI Gateway after fixing CVE-2026-90970, a flaw that could allow arbitrary command execution on unpatched instances. The company released 19.2.4, 19.3.2, and 19.4.1 and told affected users to upgrade immediately. GitLab-hosted AI Gateway users are already protected and do not need action.
Related Happenings
GitLab security patch release for CVE-2026-90970
Security Patch Release
H score41
First: 02.10.2026 19:20
Last: 02.10.2026 19:20
Sources 1
How related:
The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
About this happening:
GitLab released 19.2.4, 19.3.2, and 19.4.1 to fix CVE-2026-90970 in GitLab Self-Hosted AI Gateway, closing a critical command-execution path for vulnerable...
GitLab security patch release for CVE-2026-90970
Security Patch ReleaseHow related: The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
About this happening: GitLab released 19.2.4, 19.3.2, and 19.4.1 to fix CVE-2026-90970 in GitLab Self-Hosted AI Gateway, closing a critical command-execution path for vulnerable...
GitLab AI Gateway improper neutralization command execution security flaw (CVE-2026-90970)
Vulnerability
H score35
First: 02.10.2026 19:20
Last: 02.10.2026 19:20
Sources 1
How related:
The flaw is tracked as CVE-2026-90970. GitLab disclosed it on October 2 and rated it critical, with a CVSS score of 9.9 out of 10.
About this happening:
GitLab has fixed CVE-2026-90970, a critical improper neutralization flaw in GitLab AI Gateway that could let authenticated users with Duo Agent Platform access...
GitLab AI Gateway improper neutralization command execution security flaw (CVE-2026-90970)
VulnerabilityHow related: The flaw is tracked as CVE-2026-90970. GitLab disclosed it on October 2 and rated it critical, with a CVSS score of 9.9 out of 10.
About this happening: GitLab has fixed CVE-2026-90970, a critical improper neutralization flaw in GitLab AI Gateway that could let authenticated users with Duo Agent Platform access...
Arista security patch release for CVE-2026-93952
Security Patch Release
H score53
First: 22.09.2026 15:29
Last: 22.09.2026 15:29
Sources 1
About this happening:
Arista released fixed VeloCloud Orchestrator (VCO) builds for the 5.2 and 6.4 trains, reducing exposure for deployments tied to CVE-2026-93952. The patch set cover...
Arista security patch release for CVE-2026-93952
Security Patch ReleaseAbout this happening: Arista released fixed VeloCloud Orchestrator (VCO) builds for the 5.2 and 6.4 trains, reducing exposure for deployments tied to CVE-2026-93952. The patch set cover...
VeloCloud Orchestrator certificate-based privilege escalation (CVE-2026-93952)
Vulnerability
H score49
First: 22.09.2026 15:29
Last: 22.09.2026 15:29
Sources 1
About this happening:
CVE-2026-93952 is an actively exploited flaw in VeloCloud Orchestrator (VCO) that can let a remote attacker with no login access privilege internal functions and compr...
VeloCloud Orchestrator certificate-based privilege escalation (CVE-2026-93952)
VulnerabilityAbout this happening: CVE-2026-93952 is an actively exploited flaw in VeloCloud Orchestrator (VCO) that can let a remote attacker with no login access privilege internal functions and compr...
GitLab CE/EE security update for CVE-2026-85706
Security Patch Release
H score44
First: 14.09.2026 10:06
Last: 14.09.2026 10:06
Sources 1
About this happening:
GitLab released CE/EE fixes for CVE-2026-85706, and users were urged to patch immediately to close a repository commits API flaw that can expose credentials and se...
GitLab CE/EE security update for CVE-2026-85706
Security Patch ReleaseAbout this happening: GitLab released CE/EE fixes for CVE-2026-85706, and users were urged to patch immediately to close a repository commits API flaw that can expose credentials and se...
Timeline
-
02.10.2026 19:20 3 articles · 1h ago
GitLab warns customers to patch CVE-2026-90970 in AI Gateway
Mitigation Patch UpdateGitLab warned that CVE-2026-90970 in the GitLab AI Gateway could let an authenticated user with Duo Agent Platform access escape the prompt template sandbox via a specially crafted flow configuration and execute arbitrary commands on unpatched self-hosted instances. The company released 19.2.4, 19.3.2, and 19.4.1 for GitLab Self-Hosted AI Gateway and urged GitLab Self-Managed customers to update immediately, while GitLab-hosted AI Gateway users were already protected.
Show sources
- GitLab warns of critical RCE vulnerability in AI Gateway service — www.bleepingcomputer.com — 02.10.2026 19:20
- GitLab warns of critical RCE vulnerability in AI Gateway service — www.bleepingcomputer.com — 02.10.2026 19:20
- GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers — thehackernews.com — 02.10.2026 20:33