Database/Control plane, storage & DevOps
OpenVINO Model Server: An unauthenticated request can drive OpenVINO Model Server into unbounded resource consumption
CVSS 6.5CVE-2025-22892Control plane, storage & DevOpscurated
Impact
An unauthenticated request can drive OpenVINO Model Server into unbounded resource consumption and take the endpoint down. Cheap remote DoS against a serving tier.
Who can reach it
Anyone who can send a request to the model server.
What to do
Upgrade OpenVINO Model Server to 2024.4 or later, and put request-size and rate limits in front of the endpoint. Rolling container restart.
References
Related entries
- OpenVINO Model Server: Input-validation flaw in OpenVINO Model Server reachable without authenticationCVE-2023-31203 · OpenVINO Model ServerMedium
- IBM Storage Scale SMB protocol stack (inherited ACL handling): Files created or modified over SMB inherit permissionsCVE-2025-36104 · IBM Storage Scale SMB protocol stack (inherited ACL handling)Medium
- CephFS (ceph-fuse client): A tenant with an ordinary unprivileged UID on a node that has a CephFS volume mounted viaCVE-2025-52555 · CephFS (ceph-fuse client)Medium
- PostgreSQL pgcrypto: PGP functions emit recoverable cleartext when OpenSSL disables the cipherCVE-2026-14663 · PostgreSQL pgcrypto (pgp_sym_encrypt / pgp_pub_encrypt family)Medium
- Keycloak: authenticated user can exhaust server memory via unbounded Prometheus metric labelsCVE-2026-16100 · Keycloak (user-event Prometheus metrics)Medium
- open-iscsi iscsiuio (DHCPv6 handling): Integer underflow and out-of-bounds read in iscsiuio's DHCPv6 handlingCVE-2026-18727 · open-iscsi iscsiuio (DHCPv6 handling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.