Critical RCE in GitLab's self-hosted AI Gateway: patch now
Self-hosted only: a CVSS 9.9 bug lets a low-privilege user run commands on the gateway host. Plus Reddit sets hard sunset dates for RSS and its public API.

Copy markdown
A crafted flow can own your AI Gateway host
CVE-2026-90970 (CVSS 9.9) lets any authenticated Duo Agent Platform user escape the Jinja2 prompt-template sandbox with a specially crafted flow config and run arbitrary commands on the AI Gateway host. Only self-hosted gateways are exposed — GitLab.com, Dedicated, and GitLab-hosted gateways are not. No in-the-wild exploitation is reported yet; upgrade to the patched AI Gateway release (reported as 19.2.4 / 19.3.2 / 19.4.1 and later) and restrict who can create or edit custom flows.
Reddit sets hard dates to kill RSS and its public API
If you build anything that reads Reddit — bots, RSS readers, sentiment or training pipelines — the clock is now explicit. Reddit stops taking new public API requests on Oct 31, ends RSS feeds on Nov 13, begins cutting off unregistered apps on Jan 12, 2027, and shuts the remaining public Data API by March 2027. Migration moves to the Devvit Developer Platform (14,000+ apps already registered), with $1,000 porting bounties for registering by Nov 30.