Junglewise Threat Intelligence

CVE-2026-47478: NVIDIA Triton Inference Server use of expired file descriptor

CVE-2026-47478 · Severity: high · CVSS 7.5 · Published 2026-07-14

Technologies: Nvidia Triton Inference Server. Vendors: Nvidia.

Executive brief

NVIDIA Triton Inference Server, a platform used to deploy and manage AI models in production, is vulnerable to a flaw that can cause the service to crash. An attacker can exploit this issue remotely without needing any special permissions or user interaction. If successful, this would result in a denial of service, preventing legitimate users and applications from accessing AI inference capabilities.

Technical details

A vulnerability exists in NVIDIA Triton Inference Server for Linux (CWE-910) involving the use of an expired file descriptor. The flaw can be triggered by a remote, unauthenticated attacker over the network with low attack complexity. Successful exploitation leads to a denial of service (DoS) condition by causing the server to reference a file descriptor that is no longer valid or has been closed. The vulnerability affects versions up to and including 26.04.

Affected products

  • NVIDIA Triton Inference Server versions up to and including 26.04

Timeline

  • 2026-07-14: disclosed: Initial publication of the CVE record.

References

Related threats