CVE-2026-75871

Source
https://cve.org/CVERecord?id=CVE-2026-75871
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75871.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-75871
Published
2026-08-27T16:33:55Z
Modified
2026-09-03T03:50:24Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Server-Side Request Forgery (SSRF) in GitLab AI Gateway
Details

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect outbound model requests to an externally-controlled endpoint via a crafted inline flow configuration that overrides the HTTP Host header, resulting in disclosure of Google Cloud Vertex cloud service credentials and private signing keys.

Database specific
{
    "cna_assigner": "GitLab",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75871.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "18.10"
                },
                {
                    "fixed": "19.0.12"
                },
                {
                    "introduced": "19.1"
                },
                {
                    "fixed": "19.1.7"
                },
                {
                    "introduced": "19.2"
                },
                {
                    "fixed": "19.2.2"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / gitlab.com/gitlab-org/gitlab

Affected ranges

Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "19.1.0"
        },
        {
            "fixed": "19.1.7"
        },
        {
            "introduced": "19.2.0"
        },
        {
            "fixed": "19.2.2"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v19.*
v19.1.0-ee
v19.2.0-ee

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75871.json"