What CVSS is — why GitLab's critical flaw scored 9.9, not 10
CVSS, the Common Vulnerability Scoring System, is the international 0-to-10 scale for rating how severe a software vulnerability is. It is maintained by FIRST, the global forum of incident response teams; version 3.1 is still the most widely published and version 4.0 was released in November 2023. A base score comes from eight metrics: attack vector, attack complexity, privileges required, user interaction, scope, and the impact on confidentiality, integrity and availability. Scores of 9.0 and above are Critical. GitLab's self-hosted AI Gateway flaw CVE-2026-90970, patched on October 2, 2026, scored 9.9 rather than 10 because the attacker had to be an authenticated user. CVSS measures how bad a flaw is, not how likely it is to be exploited
The three lines
- Definition — a 0–10 severity scale run by FIRST; v3.1 dominant, v4.0 released 2023
- Inputs — eight metrics: vector, complexity, privileges, user interaction, scope, confidentiality, integrity, availability
- Reading — 9.0+ is Critical; GitLab's 9.9 lost 0.1 because login was required; severity ≠ likelihood
Key questions
- What do CVSS scores mean
- **Five bands from 0 to 10.** | Score | Rating | Typical response | |---|---|---| | 0.0 | None | — | | 0.1–3.9 | Low | Next routine patch | | 4.0–6.9 | Medium | Planned patch | | 7.0–8.9 | High | Patch quickly | | **9.0–10.0** | **Critical** | Patch now |
- What is the difference between CVSS 9.9 and 10
- **Usually one metric: whether the attacker needs to log in.** | Metric | 10.0 | 9.9 | |---|---|---| | Attack vector | Network | Network | | Complexity | Low | Low | | **Privileges required** | **None** | **Low (any account)** | | User interaction | None | None | | Scope | Changed | Changed | | C / I / A impact | High | High | GitLab's CVE-2026-90970 required a logged-in user with Duo Agent Platform access.
- CVSS 3.1 vs 4.0
- **4.0 splits out the conditions an attack really needs.** | Item | CVSS 3.1 | CVSS 4.0 | |---|---|---| | Released | June 2019 | November 2023 | | Impact spread | One 'Scope' metric | Vulnerable vs subsequent system impact | | New metric | — | Attack Requirements (AT) | | Adoption | Still most common | Growing |
"CVSS 9.9" in a security headline is a severity score out of 10. GitLab's self-hosted AI Gateway flaw CVE-2026-90970, patched on October 2, 2026, scored exactly that. Why not a perfect 10? That missing 0.1 explains how the whole system works.
1. Who keeps the scale
CVSS (Common Vulnerability Scoring System) is an open standard maintained by FIRST, the international forum of computer incident response teams. It debuted in 2005; version 3.1 (2019) is still the most widely used, and version 4.0 arrived in November 2023. Scores are assigned by the vendor or researcher disclosing a flaw, or by bodies such as the US National Vulnerability Database — and the two sometimes disagree.
2. Eight questions make a score (CVSS 3.1 base)
| Metric | Question | Worst value |
|---|---|---|
| Attack vector (AV) | From where? | Network |
| Attack complexity (AC) | Special conditions needed? | Low |
| Privileges required (PR) | Must the attacker log in? | None |
| User interaction (UI) | Must a victim click? | None |
| Scope (S) | Does damage spread to other components? | Changed |
| Confidentiality (C) | Does data leak? | High |
| Integrity (I) | Can data be altered? | High |
| Availability (A) | Can service be stopped? | High |
All eight at their worst gives 10.0. Change only privileges required to Low and the formula yields 9.9.
That is GitLab's case. A logged-in user with Duo Agent Platform access could use a crafted flow configuration to escape the prompt-template sandbox and run commands on the gateway server — over the network, no clicks, full compromise, but an account was needed.
| GitLab CVE-2026-90970 | Detail |
|---|---|
| Score | 9.9 (Critical) |
| Affected | Self-hosted AI Gateway only (GitLab.com and Dedicated unaffected) |
| Vulnerable | 18.1.6–19.2.3, 19.3.0–19.3.1, 19.4.0 |
| Fixed | 19.2.4, 19.3.2, 19.4.1 |
| Type | Template engine escape (CWE-1336) |
| This year | Second 9.9 gateway template flaw after CVE-2026-1868 in February |
3. Reading scores sensibly
Severity is not likelihood. The base score says how bad it would be; whether it will happen depends on public exploit code and confirmed attacks, such as listings in CISA's Known Exploited Vulnerabilities catalog. As of October 3, GitLab's flaw had neither.
Applicability first. A 9.9 means nothing to GitLab.com users; a 5.0 on an internet-facing server you own can be urgent. A flaw exploited before any patch exists — a zero-day — is dangerous regardless of score.
AI systems are now in scope. This flaw sat in the prompt-template layer of an AI agent feature, part of a run of AI isolation failures this autumn.
| CVSS 3.1 | CVSS 4.0 | |
|---|---|---|
| Released | June 2019 | November 2023 |
| Impact spread | One 'Scope' metric | Vulnerable and subsequent systems scored separately |
| Attack conditions | Complexity only | Complexity + Attack Requirements |
| Use | Still most common | Expanding |
4. Bottom line
CVSS gave the industry a shared ruler. But 9.9 means "check now," not "you've been hacked." Ask, in order: do I run this product and version, is a patch out, and is anyone exploiting it?
- GitLab's full vector string was not confirmed; the 9.9 explanation follows the CVSS 3.1 formula and GitLab's stated conditions.