Image Processing Flaw in vLLM Affecting Open-Source Library
CVE-2026-12491

4.8MEDIUM

What is CVE-2026-12491?

A flaw in the vLLM open-source library arises from improper management of image metadata, particularly concerning EXIF orientation and PNG transparency data during image processing. This issue can lead to the unintended loss or remapping of transparency information when images are converted to RGB, resulting in the incorrect rendering of transparent pixels. Consequently, this misinterpretation of image content can compromise the integrity of the data being processed, making it a critical concern for applications relying on accurate image analysis.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.