CVE-2026-82270: Portkey-Ai Gateway
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests with Authorization headers to reach internal services and exfiltrate provider API keys.
Affected products
- Portkey-Ai Gateway: from 1.14.0, up to and including 1.15.2
Published 2026-08-28. Last modified 2026-09-24.