Nexus Void Research

AI gateway, LLM security, MCP, API keys, Bifrost, OWASP LLM Top 10, AI infrastructure

What Is an AI Gateway? Security Risks and Controls

What is an AI gateway? How it routes LLM requests, holds your keys and MCP tools, its top security risks (like Bifrost CVE-2026-90898), and how to lock it down.

An AI gateway is a server that sits between your applications and the large language models they call, giving you one place to route requests across providers, manage API keys, enforce rate limits and budgets, log usage, and apply guardrails. It is the API gateway pattern applied to LLMs. Because an AI gateway holds every provider credential and sits in the path of all model traffic, its security is now a first-class concern: a compromised gateway exposes your keys, your prompts, and often a path to run code.

Understanding what an AI gateway is matters because these components have quietly become critical infrastructure. Tools like Bifrost, LiteLLM, Portkey, and Kong's AI Gateway route requests to OpenAI, Anthropic, Google, and 20 or more other providers behind a single endpoint, so teams can switch models, control spend, and add observability without rewriting each app. That consolidation is the value, and also the risk: everything an attacker would want, keys, traffic, and control, converges on one box.

What does an AI gateway actually do?

An AI gateway centralizes the concerns that would otherwise be scattered across every service that calls a model. In practice it provides a common set of functions.

Function

What it does

Provider routing

Sends requests to the right LLM (OpenAI, Anthropic, Google, open models) behind one API

Key management

Stores and injects provider API keys so apps never hold them directly

Rate limiting and budgets

Caps spend and request volume per team, key, or app

Caching

Reuses responses to cut cost and latency

Observability

Logs prompts, completions, tokens, and cost for auditing

Guardrails

Applies content filters, PII redaction, and policy checks

Fallbacks

Retries or reroutes when a provider fails

Increasingly, gateways also broker tool use through the Model Context Protocol (MCP), letting models call external tools and data sources. That feature is powerful and, as recent vulnerabilities show, a sharp security edge.

What are the main AI gateway security risks?

The risks are a mix of classic API-gateway problems and new AI-specific ones. The classic issues are the most damaging: because the gateway holds provider keys and fronts all traffic, an authentication or access-control failure there is a skeleton key. The clearest 2026 example is Bifrost CVE-2026-90898, a CVSS 9.8 flaw where the management API shipped with authentication disabled by default, letting an unauthenticated request register a Model Context Protocol client that made the gateway run an arbitrary command, before any handshake, as the gateway process user. One missing-auth default turned an AI gateway into an unauthenticated shell.

The recurring risk categories:

  • Missing or default-off authentication on the management API (as in Bifrost), turning administrative endpoints into open doors.

  • Credential exposure: the gateway concentrates every provider key, so a compromise leaks all of them at once.

  • MCP and tool-execution abuse: endpoints that register tools or spawn processes can become remote code execution when reachable without auth.

  • Prompt and response logging: full prompts and completions in logs can hold secrets, PII, and regulated data.

  • Server-side request forgery and injection: a gateway that fetches URLs or renders content can be steered to internal targets.

  • Excessive trust in the gateway's network position: it often sits with broad outbound access, widening blast radius.

These map onto the OWASP Top 10 for LLM Applications, which explicitly calls out sensitive information disclosure, supply-chain, and excessive-agency risks in exactly this layer.

How do you secure an AI gateway?

Treat it like the high-value, internet-adjacent control it is. A practical checklist:

  • Require authentication on every management and admin endpoint, and never run with auth disabled, even internally. Verify this by testing that an unauthenticated request is actually rejected on your build.

  • Restrict the management listener to trusted networks and keep it off the public internet.

  • Scope and rotate provider keys, and store them in a secret manager rather than the gateway's own config.

  • Lock down MCP and tool registration so only trusted, authenticated callers can add tools or spawn processes.

  • Minimize and protect logs: redact secrets and PII, and control who can read prompt and completion history.

  • Constrain outbound network access so a compromised gateway cannot freely reach internal services or the wider internet.

  • Keep it patched and inventoried, and treat the gateway as in-scope for the same continuous scanning you apply to any code you ship.

Frequently asked questions

What is an AI gateway in simple terms?
It is a single server that your apps send LLM requests to, which then routes them to the right model provider while handling keys, rate limits, logging, caching, and safety guardrails in one place.

How is an AI gateway different from an API gateway?
An AI gateway is an API gateway specialized for LLM traffic. It adds model routing across providers, token and cost tracking, prompt and completion logging, guardrails, and often MCP tool brokering, on top of the usual routing, auth, and rate limiting.

Why are AI gateways a security risk?
Because they concentrate every provider API key and sit in the path of all model traffic, so a single authentication or access-control failure can expose all keys and, when tool or MCP endpoints are exposed, lead to remote code execution, as seen in Bifrost CVE-2026-90898.

What is MCP and why does it matter for gateways?
The Model Context Protocol lets models call external tools and data sources. Its stdio transport can spawn local processes, so if a gateway lets unauthenticated callers register MCP tools, that intended behavior becomes remote command execution.

Do managed AI gateways remove the risk?
They reduce operational burden but not the fundamentals: you still control keys, access policies, logging, and which tools are exposed. Verify the provider's authentication and isolation rather than assuming a managed service is secure by default.

Our read

The AI gateway is the newest piece of critical infrastructure most teams have not put on their security map, and its risk profile is a paradox: the AI-native features get the attention, but the incidents keep coming from ordinary failures, authentication left off, keys concentrated, an admin endpoint exposed. The verifiable-by-design lesson is to treat the gateway as attack surface you must prove safe, not trust: confirm that every privileged endpoint demands an authenticated caller, that keys live in a vault, and that a compromised gateway cannot reach where it should not. As models get wired into everything, the glue between them is where the next breach lives, and the glue is exactly what most scanners never look at.

Component functions and risk categories per the OWASP Top 10 for LLM Applications; the Bifrost example and CVE detail per JFrog Security Research and the project advisory. Sources linked above.

Related: What is MCP security?, AI agent security in 2026, and our report on the GitLab AI Gateway CVE-2026-90970 RCE.

DATA SOURCES

OWASP Top 10 for LLM Applications — https://owasp.org/www-project-top-10-for-large-language-model-applications/ ; JFrog Security Research — https://jfrog.com/blog/

Liked this post? Share it:

Related posts

Related posts appear on the live page

VIEW ALL RESEARCH ->

PAGE CONTENTS

Contents appear on the live page

// FROM THE LAB

Pentesting is easy and affordable now.

Continuous VAPT you can run every month, with a report built for AI-built apps.

RUN A VAPT ->

// CYBER NETWORK

Shape the next analysis.

A curated network of security practitioners who help set our research agenda. By application.

APPLY TO JOIN ->

Get new research first

We publish original analysis and experiments on how attackers actually move. Follow along: