Nvidia Tensorrt-Llm vulnerabilities
17 known vulnerabilities affecting nvidia/tensorrt-llm.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH7MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2026-24163P3CRITICALCVSS 9.8fixed in v1.22026-05-20
CVE-2026-24163 [CRITICAL] CWE-502 CVE-2026-24163: NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could ca
NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.
nvd
CVE-2026-24142P3CRITICALCVSS 9.8fixed in v1.22026-05-20
CVE-2026-24142 [CRITICAL] CWE-502 CVE-2026-24142: NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized han
NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
nvd
CVE-2025-33255P3CRITICALCVSS 9.8fixed in v1.22026-05-20
CVE-2025-33255 [CRITICAL] CWE-502 CVE-2025-33255: NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could caus
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.
nvd
CVE-2026-24233P3HIGHCVSS 8.4≥ 0.0, ≤ v1.3.0 rc142026-07-14
CVE-2026-24233 [HIGH] CWE-502 CVE-2026-24233: NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model we
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
nvd
CVE-2025-23254P3HIGHCVSS 8.8vAll versions prior to 0.18.22025-05-01
CVE-2025-23254 [HIGH] CWE-502 CVE-2025-23254: NVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker m
NVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by local access to the TRTLLM server. A successful exploit of this vulnerability may lead to code execution, information disclosure and data tampering.
nvd
CVE-2026-47472P3HIGHCVSS 7.8≥ 0.0, ≤ v1.3.0 rc162026-07-14
CVE-2026-47472 [HIGH] CWE-502 CVE-2026-47472: NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attac
NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and denial of service.
nvd
CVE-2026-47471P3HIGHCVSS 7.5≥ 0.0, ≤ v1.3.0 rc162026-07-14
CVE-2026-47471 [HIGH] CWE-122 CVE-2026-47471: NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an at
NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service.
nvd
CVE-2026-24160P3HIGHCVSS 7.5fixed in v1.22026-05-20
CVE-2026-24160 [HIGH] CWE-690 CVE-2026-24160: NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked
NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.
nvd
CVE-2026-47473P3HIGHCVSS 7.4≥ 0.0, ≤ v1.3.0 rc162026-07-14
CVE-2026-47473 [HIGH] CWE-123 CVE-2026-47473: NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condit
NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
nvd
CVE-2026-24229P3HIGHCVSS 7.3≥ 0.0, ≤ v1.3.0 rc162026-07-14
CVE-2026-24229 [HIGH] CWE-306 CVE-2026-24229: NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component,
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
nvd
CVE-2026-24220P4MEDIUMCVSS 6.4≥ 0.0, ≤ v1.3.0 rc112026-07-14
CVE-2026-24220 [MEDIUM] CWE-502 CVE-2026-24220: NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacke
NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution.
nvd
CVE-2026-24259P4MEDIUMCVSS 6.4≥ 0.0, ≤ v1.3.0 rc122026-07-14
CVE-2026-24259 [MEDIUM] CWE-306 CVE-2026-24259: NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authent
NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
nvd
CVE-2026-24234P4MEDIUMCVSS 6.8≥ 0.0, ≤ v1.3.0 rc162026-07-14
CVE-2026-24234 [MEDIUM] CWE-918 CVE-2026-24234: NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, w
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
nvd
CVE-2026-24226P4MEDIUMCVSS 6.3≥ 0.0, ≤ v1.3.0 rc122026-07-14
CVE-2026-24226 [MEDIUM] CWE-829 CVE-2026-24226: NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper contro
NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
nvd
CVE-2026-47470P4MEDIUMCVSS 6.2≥ 0.0, ≤ v1.3.0 rc142026-07-14
CVE-2026-47470 [MEDIUM] CWE-20 CVE-2026-47470: NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint,
NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A successful exploit of this vulnerability might lead to denial of service.
nvd
CVE-2026-47475P4MEDIUMCVSS 6.2≥ 0.0, ≤ v1.3.0 rc152026-07-14
CVE-2026-47475 [MEDIUM] CWE-617 CVE-2026-47475: NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacke
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread. A successful exploit of this vulnerability might lead to denial of service.
nvd
CVE-2026-24271P4MEDIUMCVSS 6.2≥ 0.0, ≤ v1.3.0 rc142026-07-14
CVE-2026-24271 [MEDIUM] CWE-770 CVE-2026-24271: NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attack
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause allocation of GPU resources without limits or throttling. A successful exploit of this vulnerability might lead to denial of service.
nvd