<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:gitlab:ai_gateway:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3agitlabai_gateway/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 18:41:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3agitlabai_gateway/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution Vulnerability in GitLab AI Gateway</title><link>https://feed.craftedsignal.io/briefs/2026-10-gitlab-rce/</link><pubDate>Mon, 05 Oct 2026 18:41:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-gitlab-rce/</guid><description>A critical remote code execution vulnerability (CVE-2026-90970) in GitLab AI Gateway allows unauthenticated attackers to execute arbitrary code on affected installations.</description><content:encoded><![CDATA[<p>A vulnerability identified as CVE-2026-90970 affects multiple versions of the GitLab AI Gateway. This flaw allows an unauthenticated remote attacker to achieve arbitrary code execution on the underlying host. The vulnerability is present in versions 19.3.x prior to 19.3.2, versions 19.4.x prior to 19.4.1, and versions 18.1.6 through 19.2.4. GitLab released security patches on October 2, 2026, to address this flaw. Organizations running AI Gateway components should prioritize patching to the latest safe versions to mitigate the risk of full system compromise.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated attacker to gain remote code execution capabilities on the GitLab AI Gateway server. This can lead to complete system takeover, unauthorized access to sensitive data processed by the AI Gateway, or lateral movement within the network environment.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching all affected GitLab AI Gateway instances to the versions specified in the official GitLab security bulletin. Ensure that internet-facing instances are monitored for anomalous outbound traffic or unexpected child process execution from the AI Gateway service account.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>webserver</category><category>gitlab</category></item></channel></rss>