PT-2026-57575 · Helicone · Ai-Gateway

·

CVE-2026-15508

·

Published

2026-07-12

·

Updated

2026-07-13

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Helicone ai-gateway versions prior to 0.2.0-beta.31
Description A flaw in the AWS Metadata Service component allows for remote server-side request forgery (SSRF), a condition where an attacker can induce the server to make requests to an unintended location. This occurs within the build target url() function located in the ai-gateway/src/dispatcher/service.rs file due to the manipulation of the extracted path and query argument.
Recommendations As a temporary workaround, restrict access to the build target url() function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15508

Affected Products

Ai-Gateway