← Back to overview

Portkey AI Gateway versions through 1.15.2 contain a server-side request forgery (SSRF) vulnerability in the /v1/proxy/* route. The vulnerability exists because this route lacks requestValidator middleware, allowing attackers to manipulate the x-portkey-custom-host header to point to internal addresses. By forwarding requests with Authorization headers to internal services, attackers can reach otherwise inaccessible internal infrastructure. This can lead to the exfiltration of provider API keys and potentially expose sensitive internal services. The vulnerability is tracked as CVE-2026-82270 and has been reported via GitHub issues and documented by VulnCheck.

Affected products

  • Portkey AI Gateway 1.15.2

Related CVE's

  • CVE-2026-82270

Categories

  • Data Breach & Exfiltration
  • Emerging Technologies
  • Identity & Access
  • Web Technologies