CVE-2025-11915

MEDIUM

HTTP Proxy - Info Disclosure

Title source: llm
STIX 2.1

Description

Connection desynchronization between an HTTP proxy and the model backend. The fixes were rolled out for all proxies in front of impacted models by 2025-09-28. Users do not need to take any action.

Scores

CVSS v4 6.9
EPSS 0.0006
EPSS Percentile 18.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:L/U:Clear

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-444
Status published
Products (3)
Google Cloud/Vertex AI: Open Models for MaaS < 2025-09-28
Google Cloud/Vertex AI: Partner Models for MaaS < 2025-09-26
Google Cloud/Vertex AI: Self-Deployed Models < 2025-09-28
Published Oct 22, 2025
Tracked Since Feb 18, 2026