CVE-2025-33201
published 2025-12-03CVE-2025-33201: NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exceptional conditions issue by sending…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.86%
54.2th percentile
NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exceptional conditions issue by sending extra large payloads. A successful exploit of this vulnerability may lead to denial of service.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | triton_inference_server | < 25.10 | 25.10 |
| nvidia | triton_inference_server | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_oracle5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xh23-4x72-vc94: NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exceptional conditions issue by s
ghsa_unreviewed·2025-12-03
CVE-2025-33201 [HIGH] CWE-754 GHSA-xh23-4x72-vc94: NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exceptional conditions issue by s
NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exceptional conditions issue by sending extra large payloads. A successful exploit of this vulnerability may lead to denial of service.
Oracle
Oracle Oracle Commerce Risk Matrix: Workbench (Bouncy Castle Java Library) — CVE-2023-33201
vendor_oracle·2025-01-15·CVSS 5.3
CVE-2023-33201 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Workbench (Bouncy Castle Java Library) — CVE-2023-33201
Oracle Oracle Commerce Risk Matrix: Workbench (Bouncy Castle Java Library) vulnerability
CVE: CVE-2023-33201
CVSS: 5.3
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-24158 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-24158 [HIGH] CVE-2026-24158 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24158 :
Triton Inference Server vulnerability analysis and mitigation
NVIDIA Triton Inference Server contains a vulnerability in the HTTP endpoint where an attacker may cause a denial of service by providing a large compressed payload. A successful exploit of this vulnerability may lead to denial of service.
Source : NVD
## 7.5
Score
Published March 24, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Triton Inference Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:nvidia:triton_inference_server
Sources
Linux Severity HIGH Has Fix Added at: Mar 26, 2026
Linux Severity HIGH
Wiz
CVE-2025-33254 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-33254 [HIGH] CVE-2025-33254 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-33254 :
Triton Inference Server vulnerability analysis and mitigation
NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause internal state corruption. A successful exploit of this vulnerability may lead to a denial of service.
Source : NVD
## 7.5
Score
Published March 24, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Triton Inference Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:nvidia:triton_inference_server
Sources
Linux Severity HIGH Has Fix Added at: Mar 26, 2026
Linux Severity HIGH Has Fix Added at: Apr 02, 2026
## Get a CVE risk asse
Wiz
CVE-2025-33238 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-33238 [HIGH] CVE-2025-33238 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-33238 :
Triton Inference Server vulnerability analysis and mitigation
NVIDIA Triton Inference Server Sagemaker HTTP server contains a vulnerability where an attacker may cause an exception. A successful exploit of this vulnerability may lead to denial of service.
Source : NVD
## 7.5
Score
Published March 24, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Triton Inference Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:nvidia:triton_inference_server
Sources
Linux Severity HIGH Has Fix Added at: Mar 26, 2026
Linux Severity HIGH Has Fix Added at: Apr 02, 2026
## Get a CVE ri
2025-12-03
Published