CVE-2025-66405

CRITICAL

Portkey.ai Gateway < 1.14.0 - Server-Side Request Forgery via x-portkey-custom-host Header

Title source: llm
STIX 2.1

Description

Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in the x-portkey-custom-host request header. The proxy route then appends the client-specified path to perform an external fetch. This can be maliciously used by users for SSRF attacks. This vulnerability is fixed in 1.14.0.

Scores

CVSS v3 9.8
EPSS 0.0031
EPSS Percentile 22.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (3)
portkey/gateway < 1.14.0
portkey-ai/gateway 0 - 1.14.0npm
portkey.ai/gateway < 1.14.0
Published Dec 01, 2025
Tracked Since Feb 18, 2026