Skip to content
TEN Brief Ten verified stories a day 2026.10.06 KO

이 기사는 한국어로도 읽을 수 있습니다 →

Tech · 2 min read · Explainer

What CVSS is — why GitLab's critical flaw scored 9.9, not 10

CVSS, the Common Vulnerability Scoring System, is the international 0-to-10 scale for rating how severe a software vulnerability is. It is maintained by FIRST, the global forum of incident response teams; version 3.1 is still the most widely published and version 4.0 was released in November 2023. A base score comes from eight metrics: attack vector, attack complexity, privileges required, user interaction, scope, and the impact on confidentiality, integrity and availability. Scores of 9.0 and above are Critical. GitLab's self-hosted AI Gateway flaw CVE-2026-90970, patched on October 2, 2026, scored 9.9 rather than 10 because the attacker had to be an authenticated user. CVSS measures how bad a flaw is, not how likely it is to be exploited

An analyst seen from behind pointing at colorful bar charts in a sunlit security operations room

The three lines

  • Definition — a 0–10 severity scale run by FIRST; v3.1 dominant, v4.0 released 2023
  • Inputs — eight metrics: vector, complexity, privileges, user interaction, scope, confidentiality, integrity, availability
  • Reading — 9.0+ is Critical; GitLab's 9.9 lost 0.1 because login was required; severity ≠ likelihood

Key questions

What do CVSS scores mean
**Five bands from 0 to 10.** | Score | Rating | Typical response | |---|---|---| | 0.0 | None | — | | 0.1–3.9 | Low | Next routine patch | | 4.0–6.9 | Medium | Planned patch | | 7.0–8.9 | High | Patch quickly | | **9.0–10.0** | **Critical** | Patch now |
What is the difference between CVSS 9.9 and 10
**Usually one metric: whether the attacker needs to log in.** | Metric | 10.0 | 9.9 | |---|---|---| | Attack vector | Network | Network | | Complexity | Low | Low | | **Privileges required** | **None** | **Low (any account)** | | User interaction | None | None | | Scope | Changed | Changed | | C / I / A impact | High | High | GitLab's CVE-2026-90970 required a logged-in user with Duo Agent Platform access.
CVSS 3.1 vs 4.0
**4.0 splits out the conditions an attack really needs.** | Item | CVSS 3.1 | CVSS 4.0 | |---|---|---| | Released | June 2019 | November 2023 | | Impact spread | One 'Scope' metric | Vulnerable vs subsequent system impact | | New metric | — | Attack Requirements (AT) | | Adoption | Still most common | Growing |

"CVSS 9.9" in a security headline is a severity score out of 10. GitLab's self-hosted AI Gateway flaw CVE-2026-90970, patched on October 2, 2026, scored exactly that. Why not a perfect 10? That missing 0.1 explains how the whole system works.

1. Who keeps the scale

CVSS (Common Vulnerability Scoring System) is an open standard maintained by FIRST, the international forum of computer incident response teams. It debuted in 2005; version 3.1 (2019) is still the most widely used, and version 4.0 arrived in November 2023. Scores are assigned by the vendor or researcher disclosing a flaw, or by bodies such as the US National Vulnerability Database — and the two sometimes disagree.

2. Eight questions make a score (CVSS 3.1 base)

MetricQuestionWorst value
Attack vector (AV)From where?Network
Attack complexity (AC)Special conditions needed?Low
Privileges required (PR)Must the attacker log in?None
User interaction (UI)Must a victim click?None
Scope (S)Does damage spread to other components?Changed
Confidentiality (C)Does data leak?High
Integrity (I)Can data be altered?High
Availability (A)Can service be stopped?High

All eight at their worst gives 10.0. Change only privileges required to Low and the formula yields 9.9.

That is GitLab's case. A logged-in user with Duo Agent Platform access could use a crafted flow configuration to escape the prompt-template sandbox and run commands on the gateway server — over the network, no clicks, full compromise, but an account was needed.

GitLab CVE-2026-90970Detail
Score9.9 (Critical)
AffectedSelf-hosted AI Gateway only (GitLab.com and Dedicated unaffected)
Vulnerable18.1.6–19.2.3, 19.3.0–19.3.1, 19.4.0
Fixed19.2.4, 19.3.2, 19.4.1
TypeTemplate engine escape (CWE-1336)
This yearSecond 9.9 gateway template flaw after CVE-2026-1868 in February

3. Reading scores sensibly

Severity is not likelihood. The base score says how bad it would be; whether it will happen depends on public exploit code and confirmed attacks, such as listings in CISA's Known Exploited Vulnerabilities catalog. As of October 3, GitLab's flaw had neither.

Applicability first. A 9.9 means nothing to GitLab.com users; a 5.0 on an internet-facing server you own can be urgent. A flaw exploited before any patch exists — a zero-day — is dangerous regardless of score.

AI systems are now in scope. This flaw sat in the prompt-template layer of an AI agent feature, part of a run of AI isolation failures this autumn.

CVSS 3.1CVSS 4.0
ReleasedJune 2019November 2023
Impact spreadOne 'Scope' metricVulnerable and subsequent systems scored separately
Attack conditionsComplexity onlyComplexity + Attack Requirements
UseStill most commonExpanding

4. Bottom line

CVSS gave the industry a shared ruler. But 9.9 means "check now," not "you've been hacked." Ask, in order: do I run this product and version, is a patch out, and is anyone exploiting it?

  • GitLab's full vector string was not confirmed; the 9.9 explanation follows the CVSS 3.1 formula and GitLab's stated conditions.

Sources

  1. FIRST — Common Vulnerability Scoring System v3.1: Specification Document
  2. FIRST — CVSS v4.0 Specification Document
  3. The Hacker News — GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
  4. Security Affairs — CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed

Verification

Published
Last modified
Cross-check
Checked against 4 independent sources.
Unverified
  • We did not confirm GitLab's full CVSS vector string; the explanation of 9.9 follows the CVSS 3.1 formula and GitLab's stated attack conditions (an authenticated user).
  • As of October 3 no public exploit or in-the-wild use had been reported; later status is unconfirmed.
Authoring
Reviewed by a person before publication. The full process is described in the Editorial.

Ten stories, once each morning

We send the three-line summaries only; the full pieces stay on the site. One-click unsubscribe, any time.

Related