Executive brief
NVIDIA TensorRT-LLM, a library used to optimize the performance of large language models on Linux systems, contains a security flaw in how it fetches media files. An attacker could exploit this to trick the server into making unauthorized requests to internal or external systems. This could lead to the exposure of sensitive internal information or cause a disruption in service.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in NVIDIA TensorRT-LLM for Linux within its multimodal media fetching functions. The flaw (CWE-918) allows a network-accessible attacker to manipulate the library into making unintended requests. While the CVSS vector indicates a local attack vector (AV:L), the description notes the attacker is network-accessible, suggesting the library processes untrusted inputs from network sources. Successful exploitation can result in information disclosure from internal resources or a denial of service condition. The vulnerability affects versions up to and including v1.3.0 rc16.
Affected products
- NVIDIA TensorRT-LLM up to and including v1.3.0 rc16
Timeline
- 2026-07-14: advisory: Initial disclosure by NVIDIA
- 2026-07-14: disclosed