CVE-2025-11915: HTTP Desynchronisation in Vertex AI for certain third-party models
Published Oct 22, 2025
·Updated
Connection desynchronization between an HTTP proxy and the model backend. The fixes were rolled out for all proxies in front of impacted models by 2025-09-28. Users do not need to take any action.
Affected Software
1 affected component
Google Vertex AI
Event History
Oct 22, 2025
CVE Published
via MITRE·09:13 AM
Data Sourced
via MITRE·09:13 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-11915?
CVE-2025-11915 has been classified with a moderate severity level.
2
How do I fix CVE-2025-11915?
No action is required from users as the fixes were implemented for all proxies by September 28, 2025.
3
What causes CVE-2025-11915?
CVE-2025-11915 is caused by a connection desynchronization between an HTTP proxy and the model backend.
4
Which software is affected by CVE-2025-11915?
The affected software for CVE-2025-11915 includes Google Vertex AI.
5
Is there any user action required for CVE-2025-11915?
Users do not need to take any action as the vulnerability has already been addressed by the provider.