<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:35:19.152426+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333583</id>
    <title>EUVD-2026-333583</title>
    <updated>2026-10-03T11:35:19.156536+00:00</updated>
    <content>EUVD-2026-333583</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333583"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-12491</id>
    <title>fkie_cve-2026-12491</title>
    <updated>2026-10-03T11:35:19.156573+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in vLLM, an open-source library for large language model inference. This vulnerability arises from improper handling of image metadata, specifically EXIF orientation and PNG transparency (tRNS) data, during image processing. When images are converted to RGB, transparency information may be implicitly discarded or remapped, leading to unexpected rendering of transparent pixels and distortion of input content. This can result in the model misinterpreting image content, potentially affecting the integrity of processed data.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-12491"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8jr5-v98p-w75m</id>
    <title>GHSA-8jr5-v98p-w75m — vLLM: image EXIF Rotation &amp; PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations</title>
    <updated>2026-10-03T11:35:19.156608+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vllm</p>
<p>## Summary</p>
<p>Issue 1: EXIF orientation not normalized → The image orientation processed by the model differs from how humans view it, introducing interpretation bias.</p>
<p>Issue 2: PNG tRNS not explicitly flattened before converting to RGB → After conversion, transparent/semi-transparent pixels are rendered unexpectedly, making otherwise subtle overlay elements visible and distorting the input content. (This attack is similar to AlphaDog: RGBA handling is already correct in vLLM, but since tRNS permits RGB images, the correct processing path isn’t taken.)</p>
<p>Issue 3 : Pillow only loads the first frame when loading APNG or GIF files.</p>
<p>---</p>
<p>## Root Cause</p>
<p>* **Rotation**: After opening an image, `ImageOps.exif_transpose` is not called to normalize EXIF orientation.
* **Transparency**: Only **RGBA→RGB** is flattened with a background; PNGs carrying **`tRNS`** in **`P`/`L`/`RGB + tRNS`** and other non-RGBA modes take the `image.convert("RGB")` path, which implicitly discards/remaps transparency semantics.</p>
<p>---</p>
<p>## Affected Code</p>
<p>https://github.com/vllm-project/vllm/blob/16b37f3119918c1e5a39f303e0d0892c65c07a90/vllm/multimodal/image.py#L77-L84</p>
<p>https://github.com/vllm-project/vllm/blob/16b37f3119918c1e5a39f303e0d0892c65c07a90/vllm/multimodal/image.py#L37-L43</p>
<p>https://github.com/vllm-project/vllm/blob/16b37f3119918c1e5a39f303e0d0892c65c07a90/vllm/multimodal/image.py#L26-L34
&gt; Current state: `ImageOps.exif_transpose` is not used. (Although the `rescale_image_size` function ([https://githu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8jr5-v98p-w75m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3406</id>
    <title>PYSEC-2026-3406 — vLLM: image EXIF Rotation &amp; PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations</title>
    <updated>2026-10-03T11:35:19.156667+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vllm</p>
<p>## Summary</p>
<p>Issue 1: EXIF orientation not normalized → The image orientation processed by the model differs from how humans view it, introducing interpretation bias.</p>
<p>Issue 2: PNG tRNS not explicitly flattened before converting to RGB → After conversion, transparent/semi-transparent pixels are rendered unexpectedly, making otherwise subtle overlay elements visible and distorting the input content. (This attack is similar to AlphaDog: RGBA handling is already correct in vLLM, but since tRNS permits RGB images, the correct processing path isn’t taken.)</p>
<p>Issue 3 : Pillow only loads the first frame when loading APNG or GIF files.</p>
<p>---</p>
<p>## Root Cause</p>
<p>* **Rotation**: After opening an image, `ImageOps.exif_transpose` is not called to normalize EXIF orientation.
* **Transparency**: Only **RGBA→RGB** is flattened with a background; PNGs carrying **`tRNS`** in **`P`/`L`/`RGB + tRNS`** and other non-RGBA modes take the `image.convert("RGB")` path, which implicitly discards/remaps transparency semantics.</p>
<p>---</p>
<p>## Affected Code</p>
<p>https://github.com/vllm-project/vllm/blob/16b37f3119918c1e5a39f303e0d0892c65c07a90/vllm/multimodal/image.py#L77-L84</p>
<p>https://github.com/vllm-project/vllm/blob/16b37f3119918c1e5a39f303e0d0892c65c07a90/vllm/multimodal/image.py#L37-L43</p>
<p>https://github.com/vllm-project/vllm/blob/16b37f3119918c1e5a39f303e0d0892c65c07a90/vllm/multimodal/image.py#L26-L34
&gt; Current state: `ImageOps.exif_transpose` is not used. (Although the `rescale_image_size` function ([https://githu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3406"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1992</id>
    <title>WID-SEC-W-2026-1992 — vllm: Schwachstelle ermöglicht Manipulation von Daten</title>
    <updated>2026-10-03T11:35:19.156765+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vllm ausnutzen, um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1992"/>
  </entry>
</feed>
