Executive brief
NVIDIA Triton Inference Server, a platform used to deploy and manage AI models in production, is affected by a security vulnerability. An attacker could exploit this flaw to crash the server, leading to a denial of service. This would disrupt AI-driven applications and services that rely on the server for real-time processing.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in NVIDIA Triton Inference Server for Linux. The flaw can be triggered by a remote, unauthenticated attacker over the network without any user interaction. A successful exploit allows the attacker to cause a crash of the inference service, resulting in a denial of service (DoS) condition. The vulnerability is confirmed to affect versions up to and including 26.04.
Affected products
- NVIDIA Triton Inference Server <= 26.04
Timeline
- 2026-07-14: advisory: NVIDIA published the vulnerability details.
- 2026-07-14: disclosed: CVE-2026-47477 was published to the NVD.