Executive brief
NVIDIA Triton Inference Server, a platform used to deploy and manage AI models in production, is vulnerable to a flaw that can crash the service. An attacker can remotely trigger an error that the system fails to handle properly, leading to a total loss of availability for AI-driven applications. This could disrupt business operations that rely on real-time machine learning predictions.
Technical details
NVIDIA Triton Inference Server for Linux is vulnerable to a denial of service (DoS) due to an uncaught exception (CWE-248). The vulnerability can be triggered by a remote, unauthenticated attacker over the network without any user interaction. By sending a specifically crafted request that triggers an unhandled error state, the attacker can cause the server process to terminate unexpectedly. The issue affects versions up to and including 26.04.
Affected products
- NVIDIA Triton Inference Server <= 26.04
Timeline
- 2026-07-14: advisory: Initial disclosure by NVIDIA and NVD publication.