Security bulletins
The following describes all security bulletins related to Generative AI on Vertex AI.
To get the latest security bulletins delivered to you, do one of the following:
- Add the URL of this page to your feed reader.
- Add the feed URL directly to your feed reader:
https://cloud.google.com/feeds/generative-ai-on-vertex-ai-security-bulletins.xml
GCP-2025-059
Published: 2025年10月21日
Updated: 2025年10月22日
| Description | Severity | Notes |
|---|---|---|
|
2025年10月22日 Update: Added link to CVE. On September 23, 2025, we discovered a technical issue in the Vertex AI API that resulted in a limited amount of responses being misrouted between recipients for certain third-party models when using streaming requests. This issue is now resolved. Google models, e.g. Gemini, were not impacted.
Some internal proxies did not properly handle HTTP requests that
have an What should I do?
We have implemented fixes to properly address the presence of
the The fixes were rolled out for different models on separate schedules, with Anthropic models being remediated by Sep. 26, 12:45 AM PDT and all surfaces remediated by Sep. 28, 07:10 PM PDT. Affected models on Vertex AI API and the time of resolution are listed below:
|
Medium | CVE-2025-11915 |
GCP-2024-063
Published: 2024年12月06日
| Description | Severity | Notes |
|---|---|---|
|
A vulnerability was discovered in the Vertex AI API serving Gemini
multimodal requests, allowing bypass of
VPC Service Controls.
An attacker may be able to abuse the
What should I do? No actions needed. We've implemented a fix to return an error message when a media file URL is specified in the fileUri parameter and VPC Service Controls is enabled. Other use cases are unaffected. What vulnerabilities are being addressed?
The Vertex AI API serving Gemini multimodal requests lets you
include media files by specifying the URL of the media file in the
|
Medium | CVE-2024-12236 |