Helicone · Ai-Gateway · CVE-2026-15508
**Name of the Vulnerable Software and Affected Versions**
Helicone ai-gateway versions prior to 0.2.0-beta.31
**Description**
A flaw in the AWS Metadata Service component allows for remote server-side request forgery (SSRF), a condition where an attacker can induce the server to make requests to an unintended location. This occurs within the `build target url()` function located in the `ai-gateway/src/dispatcher/service.rs` file due to the manipulation of the `extracted path and query` argument.
**Recommendations**
As a temporary workaround, restrict access to the `build target url()` function to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.