Connection Desynchronization in Google Cloud's AI Models
CVE-2025-11915
What is CVE-2025-11915?
A connection desynchronization issue has been identified between the HTTP proxy and the model backend of Google Cloud's AI systems. This vulnerability could potentially allow for unexpected behavior in communications between network components and service models. Fortunately, Google Cloud has implemented fixes for all affected proxies as of September 28, 2025, ensuring that users of Vertex AI do not need to take any further action to protect their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Vertex AI: Open Models for MaaS https://cloud.google.com/vertex-ai/generative-ai/docs/maas/use-open-models 0 < 2025-09-28
Vertex AI: Partner Models for MaaS https://cloud.google.com/vertex-ai/generative-ai/docs/partner-models/use-partner-models 0 < 2025-09-26
Vertex AI: Self-Deployed Models https://cloud.google.com/vertex-ai/generative-ai/docs/model-garden/self-deployed-models 0 < 2025-09-28
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
