Junglewise Threat Intelligence

CVE-2026-75871: GitLab AI Gateway credential disclosure via HTTP Host header override

CVE-2026-75871 · Severity: high · CVSS 8.2 · Published 2026-08-27

Vendors: GitLab.

Executive brief

GitLab's AI Gateway component, used to manage AI model requests, contains a vulnerability that allows authenticated users with Duo Agent Platform access to redirect requests to attacker-controlled servers. By exploiting this flaw, an attacker can intercept and steal sensitive credentials for Google Cloud services and private signing keys, potentially compromising cloud infrastructure and data security.

Technical details

The vulnerability is a request interception and credential disclosure flaw in GitLab's AI Gateway component. An authenticated user with Duo Agent Platform access can craft a malicious inline flow configuration that overrides the HTTP Host header in outbound model requests. This allows the attacker to redirect requests to an externally-controlled endpoint, enabling interception of sensitive credentials including Google Cloud Vertex service credentials and private signing keys. The attack requires authentication and platform-level access but no user interaction, with network-reachable endpoints. Patches are available in GitLab 19.0.13, 19.1.8, 19.2.3, and later versions.

Affected products

  • GitLab AI Gateway 18.10 to 19.0.12, 19.1 to 19.1.7, 19.2 to 19.2.2

Timeline

  • 2026-08-27: disclosed

References