Portkey / Prisma AIRS AI Gateway
Portkey: custom-host routing and private-network access
Open-source Portkey gateway custom-host routing
Remediation record: 1.14.0
Case library
Selected advisories, incidents, release fixes and documented behaviours explain deployment conditions and responses. Counts reflect editorial selection, not vendor security rankings.
Sources reviewed 2026-10-07 · By OneQuill Research
16 cases
Portkey / Prisma AIRS AI Gateway
Open-source Portkey gateway custom-host routing
Remediation record: 1.14.0
Bifrost
Reachable management APIs with authentication disabled; stdio MCP registration and remote custom-plugin loading
Remediation record: Both advisories identify 2.1.0.
Envoy AI Gateway / Agent Router
MCP JSON-RPC parsing in the Envoy AI Gateway / Agent Router project
Remediation record: 0.6.0
Envoy AI Gateway / Agent Router
MCP POST-body buffering in the external-processing component
Remediation record: 1.0.0
agentgateway
Cross-namespace backend references authored by Kubernetes namespace administrators
Remediation record: 1.3.0 plus AGW_BACKEND_REF_GRANT_MODE=route-and-policy
New API
Quota settlement in affected New API release candidates
Remediation record: ≥ 1.0.0-rc.18
Kong AI Gateway
Kong AI Proxy plugin handling of Gemini streaming usage
Remediation record: 3.16.0.0 includes the stated fix.
LiteLLM
Malicious PyPI distributions, distinct from the vendor's official pinned Proxy Docker images
Remediation record: Vendor describes a clean 1.83 release and pipeline v2 on 30 March; incident response also requires containment and credential review.
GitLab AI Gateway
GitLab Duo Agent Platform flow-template processing
Remediation record: 19.2.4, 19.3.2 and 19.4.1
vLLM
PyNcclPipe KV-cache transfer in the V0 engine
Remediation record: 0.8.5
vLLM
Model-configuration loading when Python assertion checks are disabled
Remediation record: ≥ 0.22.0
vLLM
Optional prompt embeddings and base64 video/jpeg frame processing; separate findings collected in one feature-validation case
Remediation record: Original embeddings: 0.13.0. Concurrency follow-up: ≥ 0.26.0. Video frames: 0.19.0.
vLLM
Integer truncation in specific GGUF dequantisation kernels
Remediation record: Current vendor patched-version field: ≥ 0.24.0
SGLang
Feature-dependent worker serialization, replay tooling and administrative/model-loading interfaces
Remediation record: March CERT/CC update: 0.5.10, with conflicting CVE-2026-3059 metadata. A fixed release for the July group is not established by the cited July notice.
Ollama
GGUF tensor-size validation during model creation and quantization
Remediation record: Registry patched-version field: 0.17.1. Confirm inclusion of the upstream tensor-size fix in the deployed artifact.
LM Studio
Documented API authentication, network binding, remote model resolution and JIT model residency
Deployment control: Enable required authentication and scoped token permissions for shared access; approve bind addresses and remote devices; configure model residency intentionally.
Change a filter or clear your search to see more records.
How to read this research
Product coverage is a researched snapshot, not an exhaustive inventory. Category and deployment mode describe the cited offering; editions, contracts and configuration can change the scope. Selected cases illustrate evaluation questions. Advisory counts are not security rankings.
A published security finding, with prerequisites and remediation evidence.
A reported event and response, attributed to its source.
A correction recorded in release notes; not automatically a CVE.
A design choice, default or limit from official documentation.
Published by OneQuill, developer of OneVir. This is a documentary review of selected public sources, not an independent vendor security audit. Published 2026-10-07 · Modified 2026-10-07 · Sources reviewed 2026-10-07.
Report corrections through OneQuill support, with the page and primary source. Download research records (JSON) · Publishing method and templates.
A practical next step
Six A4 pages. Record the provider, version, configuration, evidence, owner and action for each topic.