High severity7.5NVD Advisory· Published Aug 28, 2026
CVE-2026-82270
CVE-2026-82270
Description
Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests with Authorization headers to reach internal services and exfiltrate provider API keys.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=1.15.2
- Range: <=1.15.2
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.