Nvidia Triton Inference Server vulnerabilities
58 known vulnerabilities affecting nvidia/triton_inference_server.
Total CVEs
58
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH40MEDIUM6
Vulnerabilities
Page 1 of 3
CVE-2026-24207P2CRITICALCVSS 9.8PoCfixed in 26.03vAll versions prior to r26.032026-05-20
CVE-2026-24207 [CRITICAL] CWE-288 CVE-2026-24207: NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authenticat
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.
nvd
CVE-2024-0087P2HIGHCVSS 8.8≥ 20.10, < 24.042024-05-14
CVE-2024-0087 [HIGH] CWE-73 CVE-2024-0087: NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging l
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
nvd
CVE-2025-23311P2CRITICALCVSS 9.8fixed in 25.07vAll versions prior to 25.072025-08-06
CVE-2025-23311 [CRITICAL] CWE-121 CVE-2025-23311: NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overfl
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially crafted HTTP requests. A successful exploit of this vulnerability might lead to remote code execution, denial of service, information disclosure, or data tampering.
nvd
CVE-2025-23317P2CRITICALCVSS 9.8fixed in 25.07vAll versions prior to 25.072025-08-06
CVE-2025-23317 [CRITICAL] CWE-122 CVE-2025-23317: NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could
NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specially crafted HTTP request. A successful exploit of this vulnerability might lead to remote code execution, denial of service, data tampering, or information disclosure.
nvd
CVE-2024-0088P3HIGHCVSS 8.1≥ 20.10, < 24.042024-05-14
CVE-2024-0088 [HIGH] CWE-119 CVE-2024-0088: NVIDIA Triton Inference Server for Linux contains a vulnerability in shared memory APIs, where a use
NVIDIA Triton Inference Server for Linux contains a vulnerability in shared memory APIs, where a user can cause an improper memory access issue by a network API. A successful exploit of this vulnerability might lead to denial of service and data tampering.
nvd
CVE-2025-23316P2CRITICALCVSS 9.8fixed in 25.08vAll versions prior to 25.082025-09-17
CVE-2025-23316 [CRITICAL] CWE-78 CVE-2025-23316: NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend,
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause a remote code execution by manipulating the model name parameter in the model control APIs. A successful exploit of this vulnerability might lead to remote code execution, denial of service, information disclosure, and
nvd
CVE-2025-23268P3CRITICALCVSS 9.8fixed in 25.07vAll versions prior to 25.072025-09-17
CVE-2025-23268 [CRITICAL] CWE-20 CVE-2025-23268: NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker may ca
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker may cause an improper input validation issue. A successful exploit of this vulnerability may lead to code execution.
nvd
CVE-2025-23319P3CRITICALCVSS 9.8fixed in 25.07vAll versions prior to 25.072025-08-06
CVE-2025-23319 [CRITICAL] CWE-805 CVE-2025-23319: NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend,
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write by sending a request. A successful exploit of this vulnerability might lead to remote code execution, denial of service, data tampering, or information disclosure.
nvd
CVE-2026-24214P3CRITICALCVSS 9.8fixed in 26.03fixed in r26.032026-05-20
CVE-2026-24214 [CRITICAL] CWE-190 CVE-2026-24214: NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, or denial of service.
nvd
CVE-2025-23310P3CRITICALCVSS 9.8fixed in 25.07vAll versions prior to 25.072025-08-06
CVE-2025-23310 [CRITICAL] CWE-121 CVE-2025-23310: NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker coul
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer overflow by specially crafted inputs. A successful exploit of this vulnerability might lead to remote code execution, denial of service, information disclosure, and data tampering.
nvd
CVE-2026-24206P3CRITICALCVSS 9.8fixed in 26.03fixed in r26.032026-05-20
CVE-2026-24206 [CRITICAL] CWE-288 CVE-2026-24206: NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authenticat
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or information disclosure.
nvd
CVE-2026-24213P3CRITICALCVSS 9.8fixed in 26.03fixed in r26.032026-05-20
CVE-2026-24213 [CRITICAL] CWE-125 CVE-2026-24213: NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, or information disclosure.
nvd
CVE-2023-31036P3HIGHCVSS 8.8fixed in 2.40vAll versions prior to 2.402024-01-12
CVE-2023-31036 [HIGH] CWE-23 CVE-2023-31036: NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is laun
NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-default command line option --model-control explicit, an attacker may use the model load API to cause a relative path traversal. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of pri
nvd
CVE-2025-23318P3CRITICALCVSS 9.8fixed in 25.07vAll versions prior to 25.072025-08-06
CVE-2025-23318 [CRITICAL] CWE-805 CVE-2025-23318: NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend,
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.
nvd
CVE-2025-23327P3CRITICALCVSS 9.1fixed in 25.05vAll versions prior to 25.052025-08-06
CVE-2025-23327 [CRITICAL] CWE-190 CVE-2025-23327: NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker coul
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer overflow through specially crafted inputs. A successful exploit of this vulnerability might lead to denial of service and data tampering.
nvd
CVE-2024-0100P3HIGHCVSS 8.1≥ 22.09, < 24.042024-05-14
CVE-2024-0100 [HIGH] CWE-73 CVE-2024-0100: NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a user c
NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a user can corrupt system files. A successful exploit of this vulnerability might lead to denial of service and data tampering.
nvd
CVE-2025-23320P3HIGHCVSS 7.5fixed in 25.07vAll versions prior to 25.072025-08-06
CVE-2025-23320 [HIGH] CWE-209 CVE-2025-23320: NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend,
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause the shared memory limit to be exceeded by sending a very large request. A successful exploit of this vulnerability might lead to information disclosure.
nvd
CVE-2025-23334P3HIGHCVSS 7.5fixed in 25.07vAll versions prior to 25.072025-08-06
CVE-2025-23334 [HIGH] CWE-125 CVE-2025-23334: NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend,
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds read by sending a request. A successful exploit of this vulnerability might lead to information disclosure.
nvd
CVE-2026-24210P3HIGHCVSS 7.5fixed in 26.03fixed in r26.032026-05-20
CVE-2026-24210 [HIGH] CWE-190 CVE-2026-24210: NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer ove
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to denial of service.
nvd
CVE-2026-24146P3HIGHCVSS 7.5fixed in 26.02vAll versions prior to r26.022026-04-07
CVE-2026-24146 [HIGH] CWE-789 CVE-2026-24146: NVIDIA Triton Inference Server contains a vulnerability where insufficient input validation and a la
NVIDIA Triton Inference Server contains a vulnerability where insufficient input validation and a large number of outputs could cause a server crash. A successful exploit of this vulnerability might lead to denial of service.
nvd
1 / 3Next →