GHSA-rv66-rgwx-xfrjHighCVSS 7.5

Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1...

Published
August 28, 2026
Last Modified
August 28, 2026

🔗 CVE IDs covered (1)

📋 Description

Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests with Authorization headers to reach internal services and exfiltrate provider API keys.

🔗 References (6)