Junglewise Threat Intelligence

CVE-2026-24227: NVIDIA TensorRT deserialization of untrusted data

CVE-2026-24227 · Severity: medium · CVSS 5.3 · Published 2026-07-14

Technologies: Nvidia TensorRT. Vendors: Nvidia.

Executive brief

NVIDIA TensorRT, a high-performance deep learning inference library, contains a security flaw in how it processes data. An attacker could provide a specially crafted file or data stream that, when processed by the software, causes it to execute unintended commands. This could lead to a disruption of service or allow an attacker to run unauthorized code on the system using the library.

Technical details

A deserialization vulnerability (CWE-502) exists in NVIDIA TensorRT due to insufficient validation of untrusted input during data restoration processes. The flaw allows a remote attacker to trigger the deserialization of malicious objects without authentication. If successfully exploited, this can lead to arbitrary code execution or a denial-of-service (DoS) condition. The vulnerability affects versions up to v10.16.1 (specifically noted as v1.3.0 rc14 in some metadata). Users are advised to refer to NVIDIA advisory 5855 for patching information.

Affected products

  • NVIDIA TensorRT v0 - v10.16.1 (up to v1.3.0 rc14)

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats