Junglewise Threat Intelligence

CVE-2026-24215: NVIDIA Triton Inference Server resource consumption in DALI backend

CVE-2026-24215 · Severity: medium · CVSS 5.7 · Published 2026-05-20

Technologies: Nvidia Triton Inference Server. Vendors: Nvidia.

Executive brief

NVIDIA Triton Inference Server, a platform used to deploy and manage AI models, contains a vulnerability in its DALI backend component. An attacker could exploit this flaw to exhaust system resources, potentially causing the server to crash or become unresponsive. This would disrupt AI-driven services and operations that rely on the server for real-time data processing.

Technical details

A vulnerability classified as CWE-400 (Uncontrolled Resource Consumption) exists in the NVIDIA Triton Inference Server DALI backend. The flaw allows a network-based attacker with low privileges to trigger excessive resource usage. Exploitation requires some level of user interaction, as indicated by the CVSS vector. If successfully exploited, the vulnerability results in a high impact on availability, potentially leading to a denial-of-service (DoS) condition. Users are advised to refer to NVIDIA security advisory 5828 for specific patching or mitigation instructions.

Affected products

  • NVIDIA Triton Inference Server

Timeline

  • 2026-05-20: disclosed: Initial publication of the CVE record.

References

Related threats