CVE WATCH / VULNERABILITY DETAIL
CVE-2026-90970
CRITICALCVSS 9.9NVD feed
Published 2 October 2026 · tracked since 3 October 2026
Description
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape th
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-103622 HIGH 8.8
- CVE-2026-103625 HIGH 8.8
- CVE-2026-39600 MEDIUM 4.7
- CVE-2026-104638 MEDIUM 5.3
- CVE-2026-104625 MEDIUM 6.3
- CVE-2026-104637 HIGH 7.3
- CVE-2026-93875 HIGH 7.2
- CVE-2026-19652 CRITICAL 9.8
- CVE-2026-104613 MEDIUM 6.3
- CVE-2026-104614 MEDIUM 6.3