All verified exploits

CVE-2026-1868 AI Gateway Jinja2 Template Injection

Deterministic critical GitLab Added cve-verified-cve-2026-1868

Confirms the GitLab AI Gateway's Duo Workflow Service evaluates user-supplied Jinja2 template expressions without blocking callables or dangerous operators. A math canary (41*271=11111) proves arbitrary expression evaluation, enabling remote code execution on the AI Gateway server.

Is your app exploitable through CVE-2026-1868?

Scan your domain free