{"data":{"id":"a91878b7-cb22-445e-bfa4-80cd88311a81","title":"CVE-2026-19889: GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 1","summary":"GitLab fixed a vulnerability in its AI Gateway component (a service that handles AI requests) affecting versions 18.9.0 through 19.2.2 that could let an authenticated user with Duo Agent Platform access redirect AI model requests to an outside server they control, potentially exposing cloud service credentials (login credentials for Google Vertex AI or AWS Bedrock).","solution":"Update to GitLab AI Gateway versions beyond 19.0.12 (for the 19.0 line), 19.1.7 (for the 19.1 line), or 19.2.2 (for the 19.2 line).","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19889","publishedAt":"2026-08-27T17:17:43.170Z","cveId":"CVE-2026-19889","cweIds":["CWE-918"],"cvssScore":"8.2","cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["Google","Amazon"],"affectedVendorsRaw":["GitLab","GitLab AI Gateway","Google Vertex AI","AWS Bedrock"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-27T17:17:43.170Z","capecIds":["CAPEC-664"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}