GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab addresses a critical remote code execution flaw in its AI Gateway service.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
Recent reports from outlets including BleepingComputer, The Hacker News, InfoQ, Forkast.news, and contributor Pasquale Pillitteri detail an urgent security development regarding GitLab. Specifically, GitLab has issued patches for a critical remote code execution vulnerability residing within its AI Gateway service. The security flaw, designated with the identifier CVE-2026-90970, carries a severe severity rating of 9.9. According to the available coverage, this vulnerability enables unauthenticated data exfiltration and allows for command execution directly on affected self-hosted servers. Media coverage heavily emphasizes the immediate nature of the threat, noting that the vulnerability is currently under active exploitation.
Outlets such as InfoQ and The Hacker News underscore that the flaw leaves self-hosted environments particularly vulnerable to unauthorized system commands and unauthorized extraction of sensitive data. In response, GitLab has made patches available to remediate CVE-2026-90970. The coordinated reporting across multiple technical publications highlights the widespread concern among system administrators managing instances of the affected AI Gateway service. The context provided by the coverage centers on the integration of artificial intelligence services within enterprise development platforms and the expanded attack surfaces such features introduce. As organizations increasingly deploy self-hosted servers running AI components like the GitLab AI Gateway, vulnerabilities of this magnitude present immediate risks to enterprise infrastructure.
The coverage points to the critical importance of timely patching, especially given that malicious actors are actively exploiting the weakness to target unpatched systems. Future developments will depend on how quickly administrators apply the provided patches across self-hosted server deployments. Coverage does not yet specify the full scope of ongoing attacks or the identity of affected organizations beyond confirming active exploitation. Observers and users of the GitLab AI Gateway service will need to monitor official channels and security advisories from GitLab for further updates regarding CVE-2026-90970 mitigation and remediation verification.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 2h ago.
Quick answers
What is the identifier of the GitLab vulnerability?
The vulnerability is tracked as CVE-2026-90970.
What is the severity score of the flaw?
The vulnerability carries a severity score of 9.9.
Is the vulnerability currently being exploited?
Yes, coverage indicates the vulnerability is under active exploitation.
Coverage (5)
- GitLab patches the 9.9 CVE-2026-90970 vulnerability in its AI Gateway Pasquale Pillitteri · 1d ago
- GitLab Patches Critical AI Gateway RCE Vulnerability forkast.news · 1d ago
- GitLab Vulnerability Under Active Exploitation Enables Unauthenticated Data Exfiltration infoq.com · 1d ago
- GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers The Hacker News · 1d ago
- GitLab warns of critical RCE vulnerability in AI Gateway service BleepingComputer · 1d ago
Topics
Related trends
Medical records giant Epic pauses product development to fix security bugs that risk patients' data
Medical records giant Epic pauses product development to fix security bugs that risk patients' data.
This new ChatGPT scam tricks you into installing malware
4 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.
Apple will limit Mac disk access as AI agents ‘substantially’ increase risk
Apple is tightening Mac disk access controls to mitigate security risks posed by the rise of AI agents.
A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
A newly reported security flaw in the ChatGPT macOS application could have allowed unauthorized access to sensitive user conversation histories.
Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Apple is restricting macOS 'Full Disk Access' controls as the rise of AI agents creates new security risks for Mac users.
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
10 news sources are covering this World story right now — PULSE is tracking how fast it spreads.