Metrics
Affected Vendors & Products
Fri, 06 Feb 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Portkey.ai
Portkey.ai gateway |
|
| CPEs | cpe:2.3:a:portkey.ai:gateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Portkey.ai
Portkey.ai gateway |
|
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Portkey-ai
Portkey-ai gateway |
|
| Vendors & Products |
Portkey-ai
Portkey-ai gateway |
Mon, 01 Dec 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in the x-portkey-custom-host request header. The proxy route then appends the client-specified path to perform an external fetch. This can be maliciously used by users for SSRF attacks. This vulnerability is fixed in 1.14.0. | |
| Title | Portkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom Host | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-02T14:11:29.966Z
Reserved: 2025-11-28T23:33:56.365Z
Link: CVE-2025-66405
Updated: 2025-12-02T14:11:22.370Z
Status : Analyzed
Published: 2025-12-01T23:15:53.567
Modified: 2026-02-06T16:44:34.367
Link: CVE-2025-66405
No data.
OpenCVE Enrichment
Updated: 2025-12-02T12:15:18Z