Executive brief
NVIDIA Triton Inference Server, a platform used to deploy and manage AI models, contains a vulnerability in its DALI backend component. An attacker could exploit this flaw to exhaust system resources, potentially causing the server to crash or become unresponsive. This would disrupt AI-driven services and operations that rely on the server for real-time data processing.
Technical details
A vulnerability classified as CWE-400 (Uncontrolled Resource Consumption) exists in the NVIDIA Triton Inference Server DALI backend. The flaw allows a network-based attacker with low privileges to trigger excessive resource usage. Exploitation requires some level of user interaction, as indicated by the CVSS vector. If successfully exploited, the vulnerability results in a high impact on availability, potentially leading to a denial-of-service (DoS) condition. Users are advised to refer to NVIDIA security advisory 5828 for specific patching or mitigation instructions.
Affected products
- NVIDIA Triton Inference Server
Timeline
- 2026-05-20: disclosed: Initial publication of the CVE record.