CVE-2026-55245
Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in core/providers/utils/fetch.go, reached through FetchAndEncodeURL for Bedrock and Vertex image or document URLs, classifies Carrier-Grade NAT 100.64.0.0/10, IPv6 6to4 2002::/16, NAT64 64:ff9b::/96 and 64:ff9b:1::/48, and deprecated IPv6 site-local fec0::/10 addresses as public. A remote attacker who controls a multimodal request URL can make the gateway fetch internal services, including a cloud instance metadata endpoint encoded through 6to4 or NAT64. This issue is fixed in version 1.5.17.
| CWE | CWE-918 |
| Vendor | maximhq |
| Product | bifrost |
| Published | Aug 28, 2026 |
| Last Updated | Aug 28, 2026 |
Get instant alerts for maximhq bifrost
Be the first to know when new unknown vulnerabilities affecting maximhq bifrost are published โ delivered to Slack, Telegram or Discord.