GitLab remediated CVE-2026-1868, a critical flaw in the Duo Workflow Service component of GitLab AI Gateway caused by improper neutralization during template expansion of user-supplied data. By submitting crafted Duo Agent Platform Flow definitions, an attacker could trigger denial of service or potentially achieve remote code execution (RCE) on the AI Gateway, turning the AI workflow feature into an execution path on the underlying gateway service.
The issue impacts self-hosted GitLab AI Gateway deployments across multiple version tracks, including versions starting at 18.1.6, 18.2.6, and 18.3.1 up to vulnerable releases such as 18.6.1, 18.7.0, and 18.8.0. GitLab released fixes in 18.6.2, 18.7.1, and 18.8.1; exploitation requires authenticated access to the GitLab instance (e.g., a compromised developer account or malicious insider), and GitLab reported the issue was discovered internally (by a GitLab team member, per reporting).

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-103 highlighting GitLab's February 6 security advisory and urging administrators to review the issue and apply the required updates. The alert reiterated the affected version ranges and the patched releases.
On February 6, 2026, GitLab published a security advisory for CVE-2026-1868 affecting self-hosted GitLab Duo AI Gateway deployments. GitLab released fixes in versions 18.6.2, 18.7.1, and 18.8.1 and advised self-managed customers to upgrade immediately.
GitLab reported that CVE-2026-1868, an insecure template expansion issue in the Duo Workflow Service of GitLab AI Gateway, was discovered internally by a team member identified as Joern. The flaw could allow denial of service or arbitrary code execution through crafted Duo Agent Platform Flow definitions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecvefeed.io
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.