# CVE-2026-55641

## Summary

- **CVE ID:** CVE-2026-55641
- **Severity:** HIGH
- **CVSS Score:** 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N)
- **CWE:** CWE-290, CWE-348, CWE-918, CWE-1327
- **Published:** Jul 10, 2026
- **Last Modified:** Jul 10, 2026

## Description

9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypass API-key authentication. In the default configuration, this exposes the /v1 proxy to upstream provider calls using stored provider credentials and allows /v1/search with the searxng provider_options.baseUrl parameter to drive server-side requests to internal or cloud-metadata hosts. This issue is fixed in version 0.5.2.

## Affected Products

- decolua — 9router (< 0.5.2)

## References

- [CNA](https://github.com/decolua/9router/security/advisories/GHSA-86m2-fcxq-5q7c)
- [CNA](https://github.com/decolua/9router/commit/b282f0554972ea35281520738759d76abcd0b0b3)
- [CNA](https://github.com/decolua/9router/releases/tag/v0.5.2)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.32%
- **EPSS Percentile:** 25.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._