Home

Description

Connection desynchronization between an HTTP proxy and the model backend. The fixes were rolled out for all proxies in front of impacted models by 2025-09-28. Users do not need to take any action.

PUBLISHED Reserved 2025-10-17 | Published 2025-10-22 | Updated 2025-10-23 | Assigner GoogleCloud




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:L/U:Clear

Problem types

CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Product status

Default status
unaffected

Any version before 2025-09-26
affected

Default status
unaffected

Any version before 2025-09-28
affected

Default status
unaffected

Any version before 2025-09-28
affected

References

cloud.google.com/...ai/generative-ai/docs/security-bulletins

cve.org (CVE-2025-11915)

nvd.nist.gov (CVE-2025-11915)

Download JSON