CVE-2026-12491
A flaw was found in vLLM, an open-source library for large language model inference. This vulnerability arises from improper handling of image metadata, specifically EXIF orientation and PNG transparency (tRNS) data, during image processing. When images are converted to RGB, transparency information may be implicitly discarded or remapped, leading to unexpected rendering of transparent pixels and distortion of input content. This can result in the model misinterpreting image content, potentially affecting the integrity of processed data.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
- EPSS probability
- 0.24%
- CWE
- CWE-115
- Published
- 2026-06-17
- Last modified
- 2026-07-08
Affected products
- vllm-project vLLM
Weakness type
Related vulnerabilities
- CVE-2026-63650 — OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be...
- CVE-2026-17566 — pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
- CVE-2026-17351 — pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
- CVE-2025-68113 — ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
- CVE-2025-55303 — Unauthorized third-party images in Astro’s _image endpoint
- CVE-2025-54584 — GitProxy is vulnerable to a packfile parsing exploit
- CVE-2025-5826 — Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability
- CVE-2025-5747 — WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability