Executive brief
NVIDIA Triton Inference Server, a platform used to deploy and manage artificial intelligence models, is affected by a security vulnerability that allows for a denial-of-service attack. An attacker can exploit this flaw to exhaust the server's resources, potentially causing the system to crash or become unresponsive. This could disrupt AI-driven business operations and services that rely on the server for real-time data processing.
Technical details
NVIDIA Triton Inference Server for Linux is vulnerable to uncontrolled resource consumption (CWE-400). The flaw allows a remote, unauthenticated attacker to send requests that exhaust system resources, leading to a denial-of-service (DoS) condition. The vulnerability is reachable over the network with low attack complexity and requires no user interaction. Affected versions include those up to and including 26.04. Security teams should monitor for official patches or mitigation guidance from NVIDIA.
Affected products
- NVIDIA Triton Inference Server <= 26.04
Timeline
- 2026-07-14: disclosed: Initial publication of CVE-2026-47479