Junglewise Threat Intelligence

CVE-2026-24142: NVIDIA TRT-LLM deserialization vulnerability

CVE-2026-24142 · Severity: medium · CVSS 6.3 · Published 2026-05-20

Technologies: Nvidia TensorRT-LLM. Vendors: Nvidia.

Executive brief

NVIDIA TensorRT-LLM, a library used to optimize the performance of large language models, contains a security flaw in how it handles data files. An attacker with local access to a system could exploit this to run unauthorized code, modify sensitive data, or view private information. This could compromise the integrity of AI models and the security of the underlying infrastructure.

Technical details

A deserialization vulnerability (CWE-502) exists in NVIDIA TensorRT-LLM (TRT-LLM) across all supported platforms. The flaw stems from the use of an unsafe serialized handle during data processing. An attacker with local access and low privileges can exploit this vulnerability by providing specially crafted serialized data. Successful exploitation can lead to arbitrary code execution, unauthorized data modification, or information disclosure, with the potential to impact components beyond the immediate library (Scope: Changed). Users are advised to refer to NVIDIA advisory 5805 for specific version patching information.

Affected products

  • NVIDIA TensorRT-LLM (TRT-LLM) All platforms

Timeline

  • 2026-05-20: disclosed: Initial publication of CVE-2026-24142
  • 2026-05-20: advisory: NVIDIA security advisory 5805 released

References

Related threats