{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/llm-proxy/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:9router:9router:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-55641"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["9router (\u003c= 0.4.80)","9router (\u003c 0.5.2)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","ssrf","api-security","web-vulnerability","authorization-bypass","llm-proxy"],"_cs_type":"advisory","_cs_vendors":["9router"],"content_html":"\u003cp\u003e9router versions 0.4.80 and earlier contain a critical authentication bypass vulnerability (CVE-2026-55641) located in the application's request guard logic. The \u003ccode\u003eisLocalRequest\u003c/code\u003e function determines if a request should be exempt from API authentication by inspecting the client-controlled \u003ccode\u003eHost\u003c/code\u003e header rather than the actual socket peer address. Because 9router defaults to binding to \u003ccode\u003e0.0.0.0\u003c/code\u003e (all interfaces) while misleadingly reporting the service as bound to \u0026quot;localhost,\u0026quot; remote attackers can reach the service and spoof \u003ccode\u003eHost: localhost\u003c/code\u003e to be treated as local users.\u003c/p\u003e\n\u003cp\u003eThis bypass grants unauthenticated access to the \u003ccode\u003e/v1\u003c/code\u003e proxy. Attackers can leverage this to exhaust the victim's paid AI provider quotas (AI relay) or conduct SSRF attacks. The SSRF primitive is particularly severe as the \u003ccode\u003e/v1/search\u003c/code\u003e endpoint allows arbitrary configuration of the outbound \u003ccode\u003ebaseUrl\u003c/code\u003e via request parameters, enabling attackers to target internal services or cloud metadata endpoints and receive the response directly in the JSON output. The issue is exacerbated by default settings that lack mandatory API key requirements for non-loopback traffic.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an internet-facing 9router instance listening on port 20128.\u003c/li\u003e\n\u003cli\u003eAttacker sends a specially crafted HTTP request to the target \u003ccode\u003e/v1/search\u003c/code\u003e or \u003ccode\u003e/v1/messages\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker sets the HTTP \u003ccode\u003eHost\u003c/code\u003e header to \u003ccode\u003elocalhost\u003c/code\u003e to bypass the \u003ccode\u003eisLocalRequest\u003c/code\u003e guard check.\u003c/li\u003e\n\u003cli\u003e9router middleware incorrectly validates the request as originating from a local source due to the spoofed header.\u003c/li\u003e\n\u003cli\u003eThe application grants the request bypass-level access, skipping the \u003ccode\u003ehasValidApiKey\u003c/code\u003e check.\u003c/li\u003e\n\u003cli\u003eFor search requests, the attacker injects an arbitrary \u003ccode\u003ebaseUrl\u003c/code\u003e (e.g., \u003ccode\u003ehttp://169.254.169.254/\u003c/code\u003e) via the \u003ccode\u003eprovider_options\u003c/code\u003e body parameter.\u003c/li\u003e\n\u003cli\u003e9router's \u003ccode\u003ehandleSearchCore\u003c/code\u003e performs a server-side \u003ccode\u003efetch\u003c/code\u003e to the attacker-supplied URL.\u003c/li\u003e\n\u003cli\u003eThe JSON response from the internal resource is reflected back to the attacker, completing the SSRF or unauthorized relay chain.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote, unauthenticated attackers to perform unauthorized actions on behalf of the victim. This results in the depletion of financial credits or usage quotas on connected AI provider accounts, the potential exfiltration of prompts and data via the AI relay, and the ability to map internal networks or exfiltrate cloud metadata via the SSRF primitive. Any deployment of 9router reachable over a network is vulnerable to this attack.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade to 9router version 0.5.2 or later immediately to patch the authentication logic.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not possible, modify the 9router configuration to bind only to \u003ccode\u003e127.0.0.1\u003c/code\u003e and ensure it is not reachable from untrusted networks.\u003c/li\u003e\n\u003cli\u003eImplement network-level access control (firewall or VPN) to restrict access to port 20128 to known, authorized IP addresses.\u003c/li\u003e\n\u003cli\u003eEnable mandatory API key authentication for all requests in the 9router settings, regardless of perceived request origin.\u003c/li\u003e\n\u003cli\u003eUse the provided POC methods against lab environments to verify that incoming requests are correctly rejected when the \u003ccode\u003eHost\u003c/code\u003e header does not match the actual connection source.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-28T21:15:48Z","date_published":"2026-08-28T21:15:37Z","id":"https://feed.craftedsignal.io/briefs/2026-08-9router-auth-bypass/","summary":"An authentication bypass in 9router 0.4.80 and earlier allows remote attackers to spoof the 'Host' header, gaining unauthorized access to API proxy endpoints, enabling quota theft via AI relay and server-side request forgery (SSRF).","title":"9router Authentication Bypass and SSRF via Host Header Spoofing","url":"https://feed.craftedsignal.io/briefs/2026-08-9router-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Llm-Proxy","version":"https://jsonfeed.org/version/1.1"}