Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:L/U:ClearDefault status
unaffected
Any version before 2025-09-26
affected
Default status
unaffected
Any version before 2025-09-28
affected
Default status
unaffected
Any version before 2025-09-28
affected
Description
Connection desynchronization between an HTTP proxy and the model backend. The fixes were rolled out for all proxies in front of impacted models by 2025-09-28. Users do not need to take any action.
Problem types
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Product status
Any version before 2025-09-26
Any version before 2025-09-28
Any version before 2025-09-28
References
cloud.google.com/...ai/generative-ai/docs/security-bulletins
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.