Executive brief
NVIDIA Triton Inference Server, a platform used to deploy and manage AI models in production, is vulnerable to a flaw that can be triggered remotely. An attacker can exploit this vulnerability to crash the server, leading to a denial-of-service. This could disrupt business operations by making AI-powered applications and services unavailable to users.
Technical details
An integer overflow vulnerability (CWE-190) exists in the NVIDIA Triton Inference Server. The flaw can be triggered by a remote, unauthenticated attacker over the network without any user interaction. By sending specially crafted requests that cause an integer wraparound, an attacker can induce a crash or unstable state in the inference service. This results in a high impact on availability (Denial of Service), though confidentiality and integrity are not reportedly affected. Users are advised to consult NVIDIA advisory 5828 for specific version patching information.
Affected products
- NVIDIA Triton Inference Server
Timeline
- 2026-05-20: disclosed
- 2026-05-20: advisory