Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55245— Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL

Quick assessment

Affected
maximhq bifrost
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Bifrost 是一个用于将请求路由至模型提供商的企业级 AI 网关。在 1.5.17 版本之前,通过针对 Bedrock 和 Vertex 的图像或文档 URL 调用 时, 中的 函数将以下地址范围错误地归类为“公共 IP”: 运营商级 NAT(CGNAT)地址段 100.64.0.0/10 IPv6 6to4 地址段 2002::/16 NAT64 地址段 64:ff9b::/96 和 64:ff9b:1::/48 已弃用的 IPv6 站点本地地址段 fec0::/10 攻击者若能控制多模态请求中的 URL(例

CVSS 8.7 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
maximhq bifrost < 1.5.17 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55245

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
Source: CVE Program / CVE List V5
Vulnerability Description
Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in core/providers/utils/fetch.go, reached through FetchAndEncodeURL for Bedrock and Vertex image or document URLs, classifies Carrier-Grade NAT 100.64.0.0/10, IPv6 6to4 2002::/16, NAT64 64:ff9b::/96 and 64:ff9b:1::/48, and deprecated IPv6 site-local fec0::/10 addresses as public. A remote attacker who controls a multimodal request URL can make the gateway fetch internal services, including a cloud instance metadata endpoint encoded through 6to4 or NAT64. This issue is fixed in version 1.5.17.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
maximhq bifrost < 1.5.17 -

II. Public POCs for CVE-2026-55245

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55245

登录查看更多情报信息。

Patches & Fixes for CVE-2026-55245 (3)

Vendor Advisories for CVE-2026-55245 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-55245

No comments yet


Leave a comment