CVE-2026-1868 Details
Description
GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in which AI Gateway was vulnerable to insecure template expansion of user supplied data via crafted Duo Agent Platform Flow definitions. This vulnerability could be used to cause Denial of Service or gain code execution on the Gateway. This has been fixed in versions 18.6.2, 18.7.1, and 18.8.1 of the GitLab AI Gateway.
A vulnerability exists in the Duo Workflow Service component of GitLab AI Gateway, affecting all versions from 18.1.6, 18.2.6, and 18.3.1 prior to 18.6.2, 18.7.1, and 18.8.1. The vulnerability arises from insecure template expansion of user-supplied data through crafted Duo Agent Platform Flow definitions. This issue could lead to a denial-of-service condition or allow code execution on the Gateway.
Users are advised to update to GitLab AI Gateway versions 18.6.2, 18.7.1, or 18.8.1. Instructions for updating GitLab Duo Self-Hosted installations can be found in the GitLab Duo Self-Hosted install documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 9, 2026CISA-ADP
Assessed Feb 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://about.gitlab.com/releases/2026/02/06/patch-release-gitlab-ai-gateway-18-8-1-released/ | [email protected] | AdvisoryRemedyVendor |
| https://gitlab.com/gitlab-org/modelops/applied-ml/code-suggestions/ai-assist/-/work_items/1850 | [email protected] | Issue TrackingPermission RequiredVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1336 | Improper Neutralization of Special Elements Used in a Template Engine | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GitLab AI Gateway | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 9, 2026 | New CVE Received | [email protected] |
Volerion