Fetching from the wire…
Security2026-08-28 · source-backed
CVE-2026-19889 and CVE-2026-75871, published August 27, let an authenticated user with Duo access redirect outbound model requests externally, affecting AI Gateway 18.9.0/18.10 through 19.0.12, 19.1 to 19.1.7 and 19.2 to 19.2.2 (NVD). Redirecting the model endpoint sends every prompt and its attached repo context to the attacker, and returns every response as trusted. Second GitLab agent-surface disclosure in two days.
Each link below shares sources, entities, or timing with this story.
AI Gateway supports Claude Code / Shared entities / Earlier coverage
Linked by a graph relationship (AI Gateway supports Claude Code); both cover August, CVE, CVSS, NVD; earlier August coverage from 2026-08-09.
Cloudflare released AI Gateway / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Cloudflare released AI Gateway); both cover August, CVE, CVSS; overlapping topics (august, request).
AI Gateway supports Claude Code / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (AI Gateway supports Claude Code); both cover August, CVE; overlapping topics (agent, attached, august, model).
Linked by a graph relationship (AI Gateway supports Claude Code); both cover AI Gateway, August; overlapping topics (agent, august, model).
AI Gateway supports Claude Code / Shared entity: CVE / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (AI Gateway supports Claude Code); both cover CVE; overlapping topics (access, agent, model, request).
AI Gateway supports Claude Code / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (AI Gateway supports Claude Code); both cover CVE, CVSS; overlapping topics (agent, context).
Linked by a graph relationship (AI Gateway supports Claude Code); both cover CVE, CVSS; overlapping topics (agent, model).
AI Gateway uses MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (AI Gateway uses MCP); both cover August, CVE, CVSS, NVD; reported by the same outlet (nvd.nist.gov).