What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
GitLab’s CVE-2026-90970 is a critical flaw in the AI Gateway, not a hardware vulnerability or a flaw that requires every GitLab user to replace equipment. If you operate an affected self-hosted AI Gateway, upgrade it to the patched release for its version branch. GitLab says its hosted gateways are already fixed, so GitLab.com, GitLab Dedicated, and self-managed GitLab instances using a GitLab-hosted gateway need no action for this advisory.
What is CVE-2026-90970?
GitLab describes CVE-2026-90970 as an improper neutralization issue in custom flow prompt templates. Under certain conditions, an authenticated user with Duo Agent Platform access could use a specially crafted flow configuration to escape the prompt-template sandbox and execute arbitrary commands on the AI Gateway. The advisory does not describe the additional conditions in detail, so this should not be characterized as an unauthenticated attack.
GitLab assigns the vulnerability a CVSS 3.1 score of 9.9, Critical, with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The score indicates assessed severity; it is not a count of affected installations or evidence of confirmed compromises. GitLab credits invisiblemeerkat for responsible disclosure.
Which AI Gateway versions are affected, and what fixes them?
Check the version of the AI Gateway itself—not the version of your GitLab application—and match it to the corresponding branch:
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors#1 Best Overall
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
| Affected AI Gateway version | First fixed AI Gateway version |
|---|---|
| 18.1.6 and later, but earlier than 19.2.4 | 19.2.4 |
| 19.3 versions earlier than 19.3.2 | 19.3.2 |
| 19.4 versions earlier than 19.4.1 | 19.4.1 |
These are AI Gateway release numbers, not GitLab application release numbers. If your self-hosted gateway falls in one of the affected ranges, upgrade to the listed fixed release in that branch. GitLab recommends upgrading affected self-hosted installations as soon as possible.
Do you need to take action?
You run a self-hosted AI Gateway
Identify its installed version and deployment type. If its version is in an affected range above, upgrade to the corresponding fixed release. The advisory addresses the gateway software; it does not call for hardware replacement or a separate security product.
Rank #2
You use GitLab-hosted AI Gateway
GitLab says it has already fixed its hosted gateways. This includes GitLab.com, GitLab Dedicated, and self-managed GitLab instances that use a GitLab-hosted AI Gateway. No action is required for this advisory in those cases.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What is not established about the flaw?
GitLab’s advisory does not say whether CVE-2026-90970 has been exploited in attacks, provide indicators of compromise, or give a detailed account of the conditions required beyond the authenticated-user access and crafted flow configuration. The Hacker News reported on the issue on October 2, 2026, but that report date should not be treated as the advisory’s publication date; the retrieved advisory content does not show one.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #3
Read GitLab’s AI Gateway patch advisory for the official version guidance. For additional reporting, see The Hacker News report dated October 2, 2026.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

