An advisory from AgentGateway revealed a security vulnerability in its configuration, specifically affecting stateful setups with multiple backends. The issue, present before version 1.4.0, allowed callers to bypass authorization rules by manipulating session IDs and route policies. This vulnerability is analogous to a rule in football (soccer) that prevents goalkeepers from handling back-passes, a rule implemented in 1992 to prevent time-wasting. The problem was identified by @0dd and fixed in AgentGateway version 1.4.0, with version 1.4.1 currently available. Separately, a critical vulnerability (CVE-2026-33017) with a CVSS score of 9.8 was found in Langflow, an open-source AI orchestration framework, allowing unauthenticated access to preview routes. AI
IMPACT Highlights security risks in AI agent infrastructure and orchestration frameworks, emphasizing the need for robust configuration and authorization.
RANK_REASON The cluster discusses security vulnerabilities in specific software tools (AgentGateway and Langflow) rather than a core AI model release or research.
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →