Junglewise Threat Intelligence

CVE-2026-24264: NVIDIA Triton Inference Server denial of service via data amplification

CVE-2026-24264 · Severity: high · CVSS 7.5 · Published 2026-07-01

Technologies: Nvidia Triton Inference Server. Vendors: Nvidia.

Executive brief

NVIDIA Triton Inference Server, a platform used to deploy and manage AI models in production, is vulnerable to a denial-of-service attack. An attacker can send specially crafted, highly compressed data that the server fails to process correctly, potentially causing the service to crash or become unresponsive. This could disrupt AI-driven business operations and application availability.

Technical details

NVIDIA Triton Inference Server for Linux is vulnerable to a data amplification attack (CWE-409) due to improper handling of highly compressed data. A remote, unauthenticated attacker can exploit this by sending malicious payloads that expand significantly upon decompression, exhausting system resources. This vulnerability is reachable over the network with low attack complexity and no user interaction required. Successful exploitation results in a denial of service (DoS) affecting the availability of the inference server. The affected versions range from 0.0 to 26.03.

Affected products

  • NVIDIA Triton Inference Server 0.0 - 26.03

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: advisory

References

Related threats