Critical Analysis: CVE-2026-42339 - New API is a large language mode (LLM) gateway and artificia... — May 11, 2026

Published 11 May 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news

AGMP Partners Initial Discovery and Context Today, May 11, 2026, we’re unpacking CVE-2026-42339, a critical server-side request forgery (SSRF) vulnerability affecting New API's LLM Gateway and AI Asset Management system, specifically versions 0.11.9-alpha.1 and prior. This is a significant finding given the increasing reliance on large language models and other AI assets across enterprise environments. When we talk about an LLM gateway, we're discussing a critical choke point, a centralized service designed to manage, secure, and route requests to various LLM providers or internal AI inference engines. It acts as an abstraction layer, handling authentication, rate limiting, data governance, and crucially, mediating network requests. This vulnerability essentially undermines a core security control that was ostensibly strengthened after the initial SSRF mitigation introduced in v0.9.0.5 (