Schema validation and resource budgeting are different controls. A structurally accepted tensor can still need concurrency-safe checks, while a frame list can consume excessive decode and processing work before inference starts.

What deployment does this concern?

Component and scope: Optional prompt embeddings and base64 video/jpeg frame processing; separate findings collected in one feature-validation case.

Affected versions / scope: Original embedding header: ≥ 0.10.2 and < 0.11.1. Follow-up header: ≥ 0.21.0. Video header: ≥ 0.7.0. These are source-specific statements.

Vendor remediation: Original embeddings: 0.13.0. Concurrency follow-up: ≥ 0.26.0. Video frames: 0.19.0.

Prompt-embedding advisories depend on enabling the feature; the follow-up explicitly requires --enable-prompt-embeds, which is off by default. The video issue concerns base64 video/jpeg frames rather than every binary video loader.

Vendor response and practical action

The upstream advisories list separate fixes. The follow-up demonstrates a concurrency-related invariant-check bypass but explicitly does not establish a live-server crash, unsafe conversion, GPU memory corruption or code execution.

Treat the vendor notice as the starting point for an applicability decision. Identify the installed artifact and configuration, document whether the prerequisite exists, and assign an owner to any required change. A public advisory does not establish that your installation was exposed or that a managed service shares the same condition.

What clients can learn

Maintain an input-feature inventory. Limit decoded dimensions, frame counts, aggregate input size and concurrent work; disable unsupported input types rather than rely on the text-only request limit.

A useful evaluation result connects a named control to evidence from the actual deployment. Keep the provider's statement, your effective configuration and a relevant demonstration together. If the result depends on a feature being disabled or a network being isolated, retain that fact with the version number so a later change triggers review.

Questions to take to your provider

  • Are prompt embeddings and video input enabled on the public route?
  • Which limits apply after base64 decoding and tensor construction?
  • Are invariant checks isolated between concurrent requests?
  • What evidence confirms each separate patched path?

Use the six-page evaluation worksheet to record evidence, ownership and actions. Continue with Running LLM inference in production: security, isolation and capacity for the wider evaluation context.

Technical detail: evidence and identifier limits

These findings share an evaluation theme but are not one vulnerability. The follow-up's unproven outcomes must not be reported as demonstrated RCE.

  • The original embedding advisory header lists ≥ 0.10.2 and < 0.11.1 while naming 0.13.0 as patched; do not silently widen the interval.
  • The upstream video advisory uses CVE-2026-34755. Red Hat describes the frame issue under CVE-2026-5497. The relationship is not counted as two independently confirmed flaws. Primary finding identifier remains GHSA-pq5c-rjhq-qp7p.

Evidence label: security advisory. Source-review date: 2026-10-07. Source publication or event date: 2026-07-27. These dates do not change merely because this article is rebuilt.

Primary sources