← All Advisories

Bifrost AI Gateway SSRF Deny-List Misclassifies CGNAT, 6to4, and NAT64 Addresses as Public, Exposing Instance Metadata to Requests Using Encoded Internal Addresses

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-55245

Key Details

CVECVE-2026-55245
CVSS Score / Version8.7 (High) / CVSS v4.0
Updated2026-09-09
Classified asCWE-918 (Server-Side Request Forgery (SSRF))

What to Know

Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in core/providers/utils/fetch.go, reached through FetchAndEncodeURL for Bedrock and Vertex image or document URLs, classifies Carrier-Grade NAT 100.64.0.0/10, IPv6 6to4 2002::/16, NAT64 64:ff9b::/96 and 64:ff9b:1::/48, and deprecated IPv6 site-local fec0::/10 addresses as public. A remote attacker who controls a multimodal request URL can make the gateway fetch internal services, including a cloud instance metadata endpoint encoded through 6to4 or NAT64. This issue is fixed in version 1.5.17. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-55245
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-55245