CODE RED

Critical RCE in GitLab AI Gateway patched

GitLab AI Gateway has a critical remote code execution flaw affecting self-hosted servers. Attackers can execute commands on affected systems.

Administrators running GitLab AI Gateway should apply the vendor's security updates.

Published 2026-10-04 11:08:21.546848+00:00 · First seen 2026-10-04 08:01:51.339284+00:00

Corroborating sources

Independent publishers report the same event within 72 hours. Methodology