<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:39:00 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-12491 — Vllm: vllm: image exif rotation &amp; png trns transparency not normalized, causing mismatch between model input and expect…</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-12491</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vllm-project vLLM, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI)&lt;/p&gt;
&lt;p&gt;A flaw was found in vLLM, an open-source library for large language model inference. This vulnerability arises from improper handling of image metadata, specifically EXIF orientation and PNG transparency (tRNS) data, during image processing. When images are converted to RGB, transparency information may be implicitly discarded or remapped, leading to unexpected rendering of transparent pixels and distortion of input content. This can result in the model misinterpreting image content, potentially affecting the integrity of processed data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vllm-project vLLM, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI)&lt;/p&gt;
&lt;p&gt;A flaw was found in vLLM, an open-source library for large language model inference. This vulnerability arises from improper handling of image metadata, specifically EXIF orientation and PNG transparency (tRNS) data, during image processing. When images are converted to RGB, transparency information may be implicitly discarded or remapped, leading to unexpected rendering of transparent pixels and distortion of input content. This can result in the model misinterpreting image content, potentially affecting the integrity of processed data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-12491</guid>
    </item>
    <item>
      <title>GHSA-8jr5-v98p-w75m — vLLM: image EXIF Rotation &amp; PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8jr5-v98p-w75m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vllm&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Issue 1: EXIF orientation not normalized → The image orientation processed by the model differs from how humans view it, introducing interpretation bias.&lt;/p&gt;
&lt;p&gt;Issue 2: PNG tRNS not explicitly flattened before converting to RGB → After conversion, transparent/semi-transparent pixels are rendered unexpectedly, making otherwise subtle overlay elements visible and distorting the input content. (This attack is similar to AlphaDog: RGBA handling is already correct in vLLM, but since tRNS permits RGB images, the correct processing path isn’t taken.)&lt;/p&gt;
&lt;p&gt;Issue 3 : Pillow only loads the first frame when loading APNG or GIF files.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;* **Rotation**: After opening an image, `ImageOps.exif_transpose` is not called to normalize EXIF orientation.
* **Transparency**: Only **RGBA→RGB** is flattened with a background; PNGs carrying **`tRNS`** in **`P`/`L`/`RGB + tRNS`** and other non-RGBA modes take the `image.convert(&amp;#34;RGB&amp;#34;)` path, which implicitly discards/remaps transparency semantics.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;https://github.com/vllm-project/vllm/blob/16b37f3119918c1e5a39f303e0d0892c65c07a90/vllm/multimodal/image.py#L77-L84&lt;/p&gt;
&lt;p&gt;https://github.com/vllm-project/vllm/blob/16b37f3119918c1e5a39f303e0d0892c65c07a90/vllm/multimodal/image.py#L37-L43&lt;/p&gt;
&lt;p&gt;https://github.com/vllm-project/vllm/blob/16b37f3119918c1e5a39f303e0d0892c65c07a90/vllm/multimodal/image.py#L26-L34
&amp;gt; Current state: `ImageOps.exif_transpose` is not used. (Although the `rescale_image_size` function ([https://githu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vllm&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Issue 1: EXIF orientation not normalized → The image orientation processed by the model differs from how humans view it, introducing interpretation bias.&lt;/p&gt;
&lt;p&gt;Issue 2: PNG tRNS not explicitly flattened before converting to RGB → After conversion, transparent/semi-transparent pixels are rendered unexpectedly, making otherwise subtle overlay elements visible and distorting the input content. (This attack is similar to AlphaDog: RGBA handling is already correct in vLLM, but since tRNS permits RGB images, the correct processing path isn’t taken.)&lt;/p&gt;
&lt;p&gt;Issue 3 : Pillow only loads the first frame when loading APNG or GIF files.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;* **Rotation**: After opening an image, `ImageOps.exif_transpose` is not called to normalize EXIF orientation.
* **Transparency**: Only **RGBA→RGB** is flattened with a background; PNGs carrying **`tRNS`** in **`P`/`L`/`RGB + tRNS`** and other non-RGBA modes take the `image.convert(&amp;#34;RGB&amp;#34;)` path, which implicitly discards/remaps transparency semantics.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;https://github.com/vllm-project/vllm/blob/16b37f3119918c1e5a39f303e0d0892c65c07a90/vllm/multimodal/image.py#L77-L84&lt;/p&gt;
&lt;p&gt;https://github.com/vllm-project/vllm/blob/16b37f3119918c1e5a39f303e0d0892c65c07a90/vllm/multimodal/image.py#L37-L43&lt;/p&gt;
&lt;p&gt;https://github.com/vllm-project/vllm/blob/16b37f3119918c1e5a39f303e0d0892c65c07a90/vllm/multimodal/image.py#L26-L34
&amp;gt; Current state: `ImageOps.exif_transpose` is not used. (Although the `rescale_image_size` function ([https://githu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8jr5-v98p-w75m</guid>
    </item>
  </channel>
</rss>
