Junglewise Threat Intelligence

CVE-2026-15508: Helicone ai-gateway SSRF in build_target_url function

CVE-2026-15508 · Severity: medium · CVSS 6.3 · Published 2026-07-12

Executive brief

Helicone ai-gateway, a tool used to manage and route requests to various AI models, contains a security vulnerability that allows attackers to redirect internal requests. By manipulating specific web addresses, an attacker could trick the gateway into scanning internal networks or accessing sensitive cloud credentials, such as those from the AWS Metadata Service. This could lead to unauthorized access to private infrastructure or the theft of service account keys.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Helicone ai-gateway versions up to 0.2.0-beta.30 within the `build_target_url` function in `ai-gateway/src/dispatcher/service.rs`. The root cause is the unsafe use of `url::Url::join()` with the user-controllable `extracted_path_and_query` argument, which fails to properly validate or sanitize path traversal sequences (e.g., '../') or absolute URL injections. A remote attacker with low privileges can exploit this to perform internal network scanning, port probing, or access sensitive cloud metadata services (like AWS IMDS at 169.254.169.254) to leak credentials. As of the advisory date, the vendor has not responded to the disclosure, and a public exploit has been released.

Affected products

  • Helicone ai-gateway up to 0.2.0-beta.30

Timeline

  • 2026-06-02: disclosed: Initial disclosure on GitHub by researcher oscar2744
  • 2026-07-12: advisory: NVD and VulDB publish CVE details

References