Portkey AI Gateway through 1.15.2 contains a server-side...
High severity
Unreviewed
Published
Aug 28, 2026
to the GitHub Advisory Database
•
Updated Aug 28, 2026
Description
Published by the National Vulnerability Database
Aug 28, 2026
Published to the GitHub Advisory Database
Aug 28, 2026
Last updated
Aug 28, 2026
Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests with Authorization headers to reach internal services and exfiltrate provider API keys.
References