Back to Database
Status published
Medium
CVE-2025-11915
HTTP Desynchronisation in Vertex AI for certain third-party models
Vulnerability Description
Connection desynchronization between an HTTP proxy and the model backend. The fixes were rolled out for all proxies in front of impacted models by 2025-09-28. Users do not need to take any action.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11915
Credits & Attribution
No credits recorded in the NVD database.
More from Google Cloud
View All →CVE-2025-9918
Zip Slip in Google SecOps SOAR allows for Remote Code Execution
High
8.7
CVE-2025-9571
Arbitrary Code Execution in Google Cloud Data Fusion via Malicious Artifact Upload
High
8.7
CVE-2025-9118
Dataform Path Traversal
Critical
10
CVE-2025-4600
HTTP Request Smuggling in Google Cloud Classic Application Load Balancer due to Improper Chunked Encoding Validation
High
8.7
CVE-2025-13428
RCE in SecOps SOAR server via user-provided Python packages
High
8.6
Affected Vendor
Google Cloud
View all reports →Affected Software
Vertex AI: Partner Models for MaaS, Vertex AI: Open Models for MaaS, Vertex AI: Self-Deployed Models
Vulnerable Versions:
0
Timeline
Official Publish:
October 22nd, 2025
Last Modified:
October 23rd, 2025
Added to House:
July 22nd, 2026