Junglewise Threat Intelligence

CVE-2026-24220: NVIDIA TensorRT-LLM unsafe deserialization in visual gen server

CVE-2026-24220 · Severity: medium · CVSS 6.4 · Published 2026-07-14

Technologies: Nvidia TensorRT-LLM. Vendors: Nvidia.

Executive brief

NVIDIA TensorRT-LLM is a library used to optimize and accelerate the performance of large language models. A security vulnerability in its visual generation server component could allow a local attacker with high privileges to execute unauthorized code on the system. This could lead to a complete compromise of the affected server, potentially impacting data confidentiality and system availability.

Technical details

An unsafe deserialization vulnerability (CWE-502) exists in the visual gen server component of NVIDIA TensorRT-LLM. The flaw is rooted in the unauthorized deserialization of ZeroMQ messages. To exploit this, an attacker requires local access to the system with high privileges and must overcome high architectural complexity (AC:H). If successfully exploited, the attacker can achieve arbitrary code execution, leading to a full compromise of confidentiality, integrity, and availability. The vulnerability affects versions up to and including v1.3.0 rc11.

Affected products

  • NVIDIA TensorRT-LLM v1.3.0 rc11 and earlier

Timeline

  • 2026-07-14: disclosed: Initial publication of CVE-2026-24220

References

Related threats