Executive brief
Portkey AI Gateway is an API routing layer that connects applications to multiple language models and AI services. The gateway's proxy endpoint lacks proper request validation, allowing attackers to intercept and redirect requests to internal systems, potentially exposing API keys and credentials that the gateway uses to authenticate with AI providers.
Technical details
This is a server-side request forgery (SSRF) vulnerability in the /v1/proxy/* route caused by missing requestValidator middleware. An attacker can set the x-portkey-custom-host header to an internal network address (e.g., localhost, private IP ranges, or metadata services) and forward requests containing Authorization headers. The missing validation allows the gateway to relay these requests to internal services without restriction, enabling exfiltration of provider API keys and unauthorized access to internal infrastructure. The vulnerability affects Portkey AI Gateway through version 1.15.2 and requires network access to the proxy endpoint; no authentication bypass is needed if the endpoint is exposed.
Affected products
- Portkey AI Gateway through 1.15.2
Timeline
- 2026-08-28: disclosed