CVE Explorer
CVE-2026-1868
GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in which AI Gateway was vulnerable to insecure template expansion of user supplied data via crafted Duo Agent Platform Flow definitions. This vulnerability could be used to cause Denial of Service or gain code execution on the Gateway. This has been fixed in versions 18.6.2, 18.7.1, and 18.8.1 of the Gi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"cpes":["cpe:2.3:a:gitlab:ai-gateway:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","product":"GitLab AI Gateway","vendor":"GitLab","versions":[{"lessThan":"18.6.2","status":"affected","version":"18.1.6","versionType":"semver"},{"lessThan":"18.7.1","status":"affected","version":"18.7.0","versionType":"semver"},{"lessThan":"18.8.1","status":"affected","version":"18.8.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c8761e4645f3f71c302c3c4b973a8f9693652a018724936734347ce665ff8ddb · sha256:ab0cf5358fd318d1… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:c8761e4645f3f71c302c3c4b973a8f9693652a018724936734347ce665ff8ddb · sha256:ab0cf5358fd318d1… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-1336","description":"CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c8761e4645f3f71c302c3c4b973a8f9693652a018724936734347ce665ff8ddb · sha256:ab0cf5358fd318d1… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://about.gitlab.com/releases/2026/02/06/patch-release-gitlab-ai-gateway-18-8-1-released/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c8761e4645f3f71c302c3c4b973a8f9693652a018724936734347ce665ff8ddb · sha256:ab0cf5358fd318d1… · /containers/cna/references/1
{"url":"https://gitlab.com/gitlab-org/modelops/applied-ml/code-suggestions/ai-assist/-/work_items/1850"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c8761e4645f3f71c302c3c4b973a8f9693652a018724936734347ce665ff8ddb · sha256:ab0cf5358fd318d1… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.