# GitLab AI Gateway RCE vulnerability patched

Published: 2026-10-05 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/5bde3ba7-f2f3-557a-8895-03e2f999c98d/gitlab-ai-gateway-rce-vulnerability-patched

> CERT-FR advisory warns a remote code execution flaw in GitLab AI Gateway affects multiple version ranges; patches available.

CERT-FR issued an advisory for a vulnerability in GitLab AI Gateway tracked as CVE-2026-90970, allowing an attacker to achieve remote arbitrary code execution. The affected versions include AI Gateway 19.3.x prior to 19.3.2, 19.4.x prior to 19.4.1, and versions from 18.1.6 up to but excluding 19.2.4.

GitLab published a patch release on 02 October 2026 addressing the issue in AI Gateway 19.4.1. No information is provided in the advisory regarding active exploitation in the wild; this is a standard vulnerability disclosure and patch notification. Organizations running self-managed GitLab AI Gateway instances within the affected version ranges should prioritize upgrading to the patched releases referenced in the official GitLab security bulletin.

## Mentioned in this report

- Vulnerabilities: CVE-2026-90970

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1262

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5bde3ba7-f2f3-557a-8895-03e2f999c98d/gitlab-ai-gateway-rce-vulnerability-patched.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
