Vulnerability in Bifrost AI Gateway Affects Internal Service Security
CVE-2026-55245
8.7HIGH
What is CVE-2026-55245?
The Bifrost AI gateway, used for routing requests to model providers, has a vulnerability arising from the isPublicIP function which incorrectly categorizes specific IP address ranges as public. These ranges include Carrier-Grade NAT and deprecated IPv6 addresses. This misclassification allows remote attackers to potentially exploit multimodal request URLs, retrieving internal services like cloud instance metadata. This issue was resolved in version 1.5.17 of the product.
Affected Version(s)
bifrost < 1.5.17
