CVE-2026-55245
published 2026-08-28CVE-2026-55245: Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in core/providers/utils/fetch.go, reached…
PriorityP353high8.7CVSS 4.0
AVNACLATNPRNUINVCNVIHVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.61%
47.5th percentile
Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in core/providers/utils/fetch.go, reached through FetchAndEncodeURL for Bedrock and Vertex image or document URLs, classifies Carrier-Grade NAT 100.64.0.0/10, IPv6 6to4 2002::/16, NAT64 64:ff9b::/96 and 64:ff9b:1::/48, and deprecated IPv6 site-local fec0::/10 addresses as public. A remote attacker who controls a multimodal request URL can make the gateway fetch internal services, including a cloud instance metadata endpoint encoded through 6to4 or NAT64. This issue is fixed in version 1.5.17.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | maximhq_bifrost_core | >= 0 < 1.5.17 | 1.5.17 |
| maximhq | bifrost | < 1.5.17 | 1.5.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
https://github.com/maximhq/bifrost/commit/54ec431fc5255ff42c36420d88549477e0b33d89https://github.com/maximhq/bifrost/pull/4092https://github.com/maximhq/bifrost/releases/tag/core/v1.5.17https://github.com/maximhq/bifrost/security/advisories/GHSA-w98g-5w9p-p3rchttps://github.com/maximhq/bifrost/security/advisories/GHSA-w98g-5w9p-p3rc
2026-08-28
Published