Логотип exploitDog
bind:CVE-2025-66405
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-66405

Количество 2

Количество 2

nvd логотип

CVE-2025-66405

2 месяца назад

Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in the x-portkey-custom-host request header. The proxy route then appends the client-specified path to perform an external fetch. This can be maliciously used by users for SSRF attacks. This vulnerability is fixed in 1.14.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-hhh5-2cvx-vmfp

2 месяца назад

Portkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom Host

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-66405

Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in the x-portkey-custom-host request header. The proxy route then appends the client-specified path to perform an external fetch. This can be maliciously used by users for SSRF attacks. This vulnerability is fixed in 1.14.0.

CVSS3: 9.8
0%
Низкий
2 месяца назад
github логотип
GHSA-hhh5-2cvx-vmfp

Portkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom Host

0%
Низкий
2 месяца назад

Уязвимостей на страницу