Triton Inference Server: RCE / privesc / data tampering via model-load path traversal (`--model-control explicit`)
CVSS 7.5CVE-2023-31036NVIDIA / GPU stackcurated
Impact
RCE / privesc / data tampering via model-load path traversal (--model-control explicit)
Who can reach it
Authenticated user of the inference endpoint; malicious model repo
What to do
Upgrade Triton to 2.40+; rebuild inference serving images; disable explicit model control on multi-tenant endpoints
References
Related entries
- Triton Inference Server: concurrent requests trigger a race condition that crashes the server (remote DoS)CVE-2025-33238 · Triton Inference ServerHigh
- Triton Inference Server: DoS via memory exhaustion on malformed inputCVE-2026-24146 · Triton Inference ServerHigh
- Triton Inference Server: Arbitrary file access via unsafe path operationsCVE-2026-24209 · Triton Inference ServerHigh
- Triton Inference Server: DoS / memory corruption (integer overflow in buffer allocation)CVE-2026-24210 · Triton Inference ServerHigh
- Triton Inference Server: DoS via improper exception handlingCVE-2026-24264 · Triton Inference ServerHigh
- Triton Inference Server: DoS via resource exhaustionCVE-2026-47476 · Triton Inference ServerHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.