The documented SSRF lets the gateway make requests to destinations that should not be selectable by an application caller. The business concern is the gateway's network authority: credentials and access intended for a trusted operator can become reachable through an untrusted request.

What deployment does this concern?

Component and scope: Open-source Portkey gateway custom-host routing.

Affected versions / scope: < 1.14.0

Vendor remediation: 1.14.0

An application caller can influence a custom upstream host on an affected open-source gateway. A useful attack also depends on the gateway being able to reach a private destination or metadata service.

Vendor response and practical action

The vendor identifies 1.14.0 as patched. Upgrade the affected distribution, restrict custom-host selection and enforce outbound network rules that also cover resolved addresses and redirects.

Treat the vendor notice as the starting point for an applicability decision. Identify the installed artifact and configuration, document whether the prerequisite exists, and assign an owner to any required change. A public advisory does not establish that your installation was exposed or that a managed service shares the same condition.

What clients can learn

A provider name in a route is only the start of the decision. Check the actual host and network destination at dispatch time. A tenant should not gain the gateway's access to internal services by changing an endpoint header.

A useful evaluation result connects a named control to evidence from the actual deployment. Keep the provider's statement, your effective configuration and a relevant demonstration together. If the result depends on a feature being disabled or a network being isolated, retain that fact with the version number so a later change triggers review.

Questions to take to your provider

  • Can an application key set a custom host or base URL?
  • Are private, loopback and metadata destinations blocked after DNS resolution?
  • Do redirects and fallback endpoints pass the same destination checks?
  • Which installed build and regression evidence establish remediation?

Use the six-page evaluation worksheet to record evidence, ownership and actions. Continue with AI gateway security: protect the boundaries that matter for the wider evaluation context.

Technical detail: evidence and identifier limits

The advisory does not establish that every managed Portkey or Prisma AIRS deployment was affected. A product-family name is insufficient evidence of exposure.

  • Primary identifier: GHSA-hhh5-2cvx-vmfp. Vendor mapping: CVE-2025-66405.

Evidence label: security advisory. Source-review date: 2026-10-07. Source publication or event date: 2025-12-01. These dates do not change merely because this article is rebuilt.

Primary sources