GitLab’s CVE-2026-90970 is a critical flaw in the AI Gateway, not a hardware vulnerability or a flaw that requires every GitLab user to replace equipment. If you operate an affected self-hosted AI Gateway, upgrade it to the patched release for its version branch. GitLab says its hosted gateways are already fixed, so GitLab.com, GitLab Dedicated, and self-managed GitLab instances using a GitLab-hosted gateway need no action for this advisory.
What is CVE-2026-90970?
GitLab describes CVE-2026-90970 as an improper neutralization issue in custom flow prompt templates. Under certain conditions, an authenticated user with Duo Agent Platform access could use a specially crafted flow configuration to escape the prompt-template sandbox and execute arbitrary commands on the AI Gateway. The advisory does not describe the additional conditions in detail, so this should not be characterized as an unauthenticated attack.
GitLab assigns the vulnerability a CVSS 3.1 score of 9.9, Critical, with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The score indicates assessed severity; it is not a count of affected installations or evidence of confirmed compromises. GitLab credits invisiblemeerkat for responsible disclosure.
Which AI Gateway versions are affected, and what fixes them?
Check the version of the AI Gateway itself—not the version of your GitLab application—and match it to the corresponding branch:
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
| Affected AI Gateway version | First fixed AI Gateway version |
|---|---|
| 18.1.6 and later, but earlier than 19.2.4 | 19.2.4 |
| 19.3 versions earlier than 19.3.2 | 19.3.2 |
| 19.4 versions earlier than 19.4.1 | 19.4.1 |
These are AI Gateway release numbers, not GitLab application release numbers. If your self-hosted gateway falls in one of the affected ranges, upgrade to the listed fixed release in that branch. GitLab recommends upgrading affected self-hosted installations as soon as possible.
Do you need to take action?
You run a self-hosted AI Gateway
Identify its installed version and deployment type. If its version is in an affected range above, upgrade to the corresponding fixed release. The advisory addresses the gateway software; it does not call for hardware replacement or a separate security product.
Rank #2
You use GitLab-hosted AI Gateway
GitLab says it has already fixed its hosted gateways. This includes GitLab.com, GitLab Dedicated, and self-managed GitLab instances that use a GitLab-hosted AI Gateway. No action is required for this advisory in those cases.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What is not established about the flaw?
GitLab’s advisory does not say whether CVE-2026-90970 has been exploited in attacks, provide indicators of compromise, or give a detailed account of the conditions required beyond the authenticated-user access and crafted flow configuration. The Hacker News reported on the issue on October 2, 2026, but that report date should not be treated as the advisory’s publication date; the retrieved advisory content does not show one.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
Read GitLab’s AI Gateway patch advisory for the official version guidance. For additional reporting, see The Hacker News report dated October 2, 2026.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

