Junglewise Threat Intelligence

CVE-2026-24209: NVIDIA Triton Inference Server path traversal in service endpoint

CVE-2026-24209 · Severity: high · CVSS 7.5 · Published 2026-05-20

Technologies: Nvidia Triton Inference Server. Vendors: Nvidia.

Executive brief

NVIDIA Triton Inference Server, a platform used to deploy and manage AI models in production, is affected by a path traversal vulnerability. An unauthenticated attacker can exploit this flaw over the network to disrupt the server's operations. This could lead to a denial-of-service condition, preventing legitimate users and applications from accessing AI inference services.

Technical details

A path traversal vulnerability (CWE-22) exists in NVIDIA Triton Inference Server. The flaw allows an unauthenticated remote attacker to provide specially crafted input that bypasses directory restrictions. According to the CVSS vector, the attack is low complexity and requires no user interaction or privileges. Successful exploitation results in a high impact on availability, potentially crashing the service or making it unresponsive (Denial of Service). While the vulnerability is categorized as path traversal, the reported impact is limited to availability rather than data confidentiality or integrity.

Affected products

  • NVIDIA Triton Inference Server

Timeline

  • 2026-05-20: advisory: Initial disclosure by NVIDIA and NVD publication.

References

Related threats