Database/Control plane, storage & DevOps
OpenVINO Model Server: Input-validation flaw in OpenVINO Model Server reachable without authentication
CVSS 4.3CVE-2023-31203Control plane, storage & DevOpscurated
Impact
Input-validation flaw in OpenVINO Model Server reachable without authentication. Same exposure profile as the later Model Server issues - it sits on the inference request path.
Who can reach it
Anything that can reach the serving endpoint.
What to do
Upgrade to the 2022.3 or later Model Server build shipped with OpenVINO 2023. Container update and rolling restart.
References
Related entries
- OpenVINO Model Server: An unauthenticated request can drive OpenVINO Model Server into unbounded resource consumptionCVE-2025-22892 · OpenVINO Model ServerMedium
- GitLab: crafted Git ref names make the web UI show different content than the downloaded archiveCVE-2025-12506 · GitLab CE/EE (Git reference name resolution)Medium
- Kibana: Open redirect leading to SSRF via a specially crafted URLCVE-2025-25012 · KibanaMedium
- Grafana: alert rules API returns rules from folders the user cannot readCVE-2026-13719 · Grafana (alert rules API list endpoint, folder authorization)Medium
- GitLab EE: developer-role user can influence the execution environment of Pipeline Execution Policy jobsCVE-2026-15387 · GitLab EE (Pipeline Execution Policy enforcement jobs, job dependency handling)Medium
- GitLab EE: Security Manager role can run arbitrary CI/CD jobs and read protected variablesCVE-2026-16794 · GitLab EE (compliance framework management authorization)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.