Junglewise Threat Intelligence

CVE-2025-66405: Portkey.ai Gateway Server-Side Request Forgery in custom host header

CVE-2025-66405 · Severity: medium · CVSS 4 · Published 2025-12-02

Technologies: Portkey.ai Gateway. Vendors: npm.

Executive brief

Portkey.ai Gateway is an API gateway that routes requests to external services. The gateway improperly validates the x-portkey-custom-host request header, allowing attackers to redirect requests to arbitrary internal systems—such as AWS metadata services or other private network hosts—to steal sensitive data or gain unauthorized access to internal infrastructure.

Technical details

The vulnerability is a Server-Side Request Forgery (CWE-918) in the gateway's request processing function. The x-portkey-custom-host HTTP header is used by the proxy route to determine the destination baseURL and is appended with a client-specified path for an external fetch, but the value is passed to the internal HTTP request function with insufficient validation or sanitization. An attacker can supply a malicious custom host header value to force the server to make requests to arbitrary hosts on the internal network, including non-routable IP addresses, loopback addresses, private networks, and metadata endpoints. No authentication is required; the attack vector is network-based. The vulnerability affects all versions prior to 1.14.0, which implements an allow-list policy that validates custom host inputs and explicitly blocks requests to sensitive endpoints.

Affected products

  • Portkey.ai Gateway <1.14.0

Timeline

  • 2025-12-02: disclosed
  • 2025-12-02: patched: Fixed in version 1.14.0

References