Executive brief
NVIDIA Triton Inference Server, a platform used to deploy and manage AI models in production, is affected by a memory management vulnerability. An attacker can exploit this flaw to cause the server to run out of memory, leading to a denial-of-service condition. This could disrupt AI-driven business operations and application availability.
Technical details
NVIDIA Triton Inference Server for Linux is vulnerable to a memory leak (CWE-401). The flaw occurs when the application fails to release memory after its effective lifetime, which can be triggered by a remote, unauthenticated attacker over the network. Successful exploitation allows an attacker to exhaust system memory resources, resulting in a denial-of-service (DoS) state. The vulnerability affects versions up to and including 26.04.
Affected products
- NVIDIA Triton Inference Server <= 26.04
Timeline
- 2026-07-14: advisory: NVIDIA published the vulnerability details.
- 2026-07-14: disclosed: CVE-2026-47482 was added to the NVD dataset.