maximhq has 3 CVEs on record. 3 were published in the last 90 days. The median CVSS is 8.9 (high), with 1 rated critical. Most affected products: github.com/maximhq/bifrost/transports (2), github.com/maximhq/bifrost/core (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.9
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Products
- github.com/maximhq/bifrost/transports 2
- github.com/maximhq/bifrost/core 1
Worst active — by depth score
CVE-2026-90898Critical· 9.8Bifrost registers MCP clients through its management API54CVE-2026-86242High· 8.1Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false)45CVE-2026-55245HighBifrost is an enterprise AI gateway for routing requests to model providers41
maximhq vulnerabilities
CVEs affecting maximhq, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-90898Critical· 9.8Bifrost registers MCP clients through its management API
Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_conf…
CVE-2026-86242High· 8.1Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false)
Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). T…
CVE-2026-55245HighBifrost is an enterprise AI gateway for routing requests to model providers
Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in core/providers/utils/fetch.go, reached through FetchAndEncodeURL for Bedrock and Vertex image or document URLs, clas…