← nejvýznamnější zprávy · všechny zprávy

poslední zpráva · zachyceno

SPOJENO AI

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...]

Číst originál na BleepingComputer →

4 zprávy z 4 zdrojů · první · zachyceno CZ · EN/orig

GitLab FI CA US

tg: zranitelnost tg: novinka v produktu tp: AI

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-90970 9.9 3.1 · GitLab – –

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.9.

Tohle CVE jsem vytáhl z širšího textu článku: CVE-2026-85706. Neukazuju u něj proto fakta z katalogů výše, a to preventivně, protože článek se na něj mohl jen odkazovat, třeba jako na starší kauzu.

Jak se o tom psalo 4

  1. · zachyceno · NCSC-FI FI

    GitLab AI Gateway Critical Patch Release: 19.2.4, 19.3.2, and 19.4.1

    Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.9, CVEs: CVE-2026-90970, Summary: GitLab have released versions 19.2.4, 19.3.2, and 19.4.1 of the GitLab AI Gateway. These versions contain a critical security fix for GitLab Self-Hosted AI Gateway, and we strongly recommend that all GitLab Self-Managed customers with GitLab Self-Hosted AI Gateway installations update to one of these versions immediately. We have conducted targeted outreach to Self…

  2. · Cyber Centre Kanada CA

    GitLab security advisory (AV26-994)

    Serial Number: AV26-994 Date: October 2, 2026 As of October 2, 2026, GitLab is affected by a vulnerability in the following product: GitLab AI Gateway Prior to 19.2.4 Prior to 19.3.2 Prior to 19.4.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. GitLab AI Gateway Critical Patch Release: 19.2.4, 19.3.2, and 19.4.1 GitLab release notes | GitLab Docs

  3. · BleepingComputer US nadpis události

    GitLab warns of critical RCE vulnerability in AI Gateway service

    GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...]

  4. · zachyceno · GitLab Security US

    GitLab AI Gateway Critical Patch Release: 19.2.4, 19.3.2, and 19.4.1

    We have released versions 19.2.4, 19.3.2, and 19.4.1 of the GitLab AI Gateway. These versions contain a critical security fix for GitLab Self-Hosted AI Gateway, and we strongly recommend that all GitLab Self-Managed customers with GitLab Self-Hosted AI Gateway installations update to one of these versions immediately. We have conducted targeted outreach to Self-Hosted AI Gateway customers prior to this release post with this guidance. A fix has already been deployed for GitLab-hosted AI…