A flaw was found in vLLM, an open-source library for large language model inference. This vulnerability arises from improper handling of image metadata, specifically EXIF orientation and PNG transparency (tRNS) data, during image processing. When images are converted to RGB, transparency information may be implicitly discarded or remapped, leading to unexpected rendering of transparent pixels and distortion of input content. This can result in the model misinterpreting image content, potentially affecting the integrity of processed data.
History

Wed, 17 Jun 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 17 Jun 2026 11:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in vLLM, an open-source library for large language model inference. This vulnerability arises from improper handling of image metadata, specifically EXIF orientation and PNG transparency (tRNS) data, during image processing. When images are converted to RGB, transparency information may be implicitly discarded or remapped, leading to unexpected rendering of transparent pixels and distortion of input content. This can result in the model misinterpreting image content, potentially affecting the integrity of processed data.
Title Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectations
First Time appeared Redhat
Redhat ai Inference Server
Redhat enterprise Linux Ai
Redhat openshift Ai
Weaknesses CWE-115
CPEs cpe:/a:redhat:ai_inference_server:3
cpe:/a:redhat:enterprise_linux_ai:3
cpe:/a:redhat:openshift_ai
Vendors & Products Redhat
Redhat ai Inference Server
Redhat enterprise Linux Ai
Redhat openshift Ai
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-06-17T14:47:57.047Z

Reserved: 2026-06-17T07:24:01.437Z

Link: CVE-2026-12491

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-06-10T00:00:00Z

Links: CVE-2026-12491 - Bugzilla

cve-icon OpenCVE Enrichment

No data.