Executive brief
NVIDIA Triton Inference Server, a platform used to deploy and manage AI models in production, is vulnerable to a denial-of-service attack. An attacker can exploit this flaw to exhaust system resources, potentially causing the server to crash or become unresponsive. This could disrupt AI-driven business operations and services that rely on real-time model predictions.
Technical details
NVIDIA Triton Inference Server for Linux is affected by an uncontrolled resource consumption vulnerability (CWE-400). The flaw allows a remote, unauthenticated attacker to trigger excessive resource usage via the network without requiring user interaction. A successful exploit can lead to a complete Denial of Service (DoS) by exhausting available system resources. The vulnerability is confirmed to affect versions up to and including 26.04.
Affected products
- NVIDIA Triton Inference Server <= 26.04
Timeline
- 2026-07-14: disclosed: Initial publication of CVE-2026-47476
- 2026-07-14: advisory