A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* endpoints are expected to enforce API key validation. However, the POST /invocations endpoint failed to do so, resulting in an authentication bypass. This vulnerability allows unauthorized users to access the same inference features available on protected endpoints, potentially exposing sensitive functionality or allowing unintended access to backend resources.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 01 Jul 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* endpoints are expected to enforce API key validation. However, the POST /invocations endpoint failed to do so, resulting in an authentication bypass. This vulnerability allows unauthorized users to access the same inference features available on protected endpoints, potentially exposing sensitive functionality or allowing unintended access to backend resources. |
Title | ai-inference-server: Authentication Bypass via Unprotected Inference Endpoint in API | Ai-inference-server: authentication bypass via unprotected inference endpoint in api |
First Time appeared |
Redhat
Redhat ai Inference Server |
|
CPEs | cpe:/a:redhat:ai_inference_server:3 | |
Vendors & Products |
Redhat
Redhat ai Inference Server |
|
References |
|
Mon, 30 Jun 2025 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | |
Title | ai-inference-server: Authentication Bypass via Unprotected Inference Endpoint in API | |
Weaknesses | CWE-306 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published: 2025-07-01T13:16:17.180Z
Updated: 2025-07-01T13:30:18.432Z
Reserved: 2025-06-30T09:05:19.410Z
Link: CVE-2025-6920

Updated: 2025-07-01T13:30:14.637Z

Status : Received
Published: 2025-07-01T14:15:41.690
Modified: 2025-07-01T14:15:41.690
Link: CVE-2025-6920
