Junglewise Threat Intelligence

CVE-2026-47628: NVIDIA Triton Inference Server resource exhaustion denial of service

CVE-2026-47628 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Nvidia Triton Inference Server, Linux Kernel. Vendors: Nvidia, Linux.

Executive brief

NVIDIA Triton Inference Server is a widely-used inference platform that deploys machine learning models at scale. This vulnerability allows an attacker to trigger unlimited resource allocation, exhausting memory and CPU, which causes the service to become unavailable and disrupts AI model serving for dependent applications and users.

Technical details

The vulnerability is a resource exhaustion / denial of service issue in NVIDIA Triton Inference Server for Linux where an attacker can trigger unbounded allocation of memory or other system resources. The flaw allows an attacker to exhaust available resources without limits, leading to denial of service. The attack vector appears to be network-based, though specific preconditions (such as authentication requirements or specific request types) are not detailed in the available advisory content. Patches or fixes from NVIDIA are expected as part of the security bulletin referenced in the advisory.

Affected products

  • NVIDIA Triton Inference Server <UNKNOWN>

Timeline

  • 2026-08-18: disclosed

References

Related threats