Junglewise Threat Intelligence

CVE-2026-47472: NVIDIA TensorRT-LLM deserialization in IPC layer

CVE-2026-47472 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Nvidia TensorRT-LLM. Vendors: Nvidia.

Executive brief

NVIDIA TensorRT-LLM, a library used to optimize the performance of large language models, contains a security flaw in how its internal components communicate with each other. A local attacker with basic user access could exploit this to run unauthorized commands, steal sensitive data, or crash the system. This could lead to a full compromise of the machine running the AI models.

Technical details

A deserialization vulnerability (CWE-502) exists in the inter-process communication (IPC) layer of NVIDIA TensorRT-LLM. The flaw is triggered when the library processes untrusted data during communication between different processes on the same host. An attacker with local, same-user privileges can exploit this by providing a specially crafted payload that, when deserialized, allows for arbitrary code execution. The vulnerability affects versions up to and including v1.3.0 rc16. Successful exploitation grants the attacker the ability to execute code, access sensitive memory, or cause a denial-of-service condition.

Affected products

  • NVIDIA TensorRT-LLM up to and including v1.3.0 rc16

Timeline

  • 2026-07-14: advisory: Initial publication of CVE-2026-47472 by NVIDIA

References

Related threats