Triton Inference Server: RCE / privesc via input-validation failure
CVSS 8.0CVE-2025-23268NVIDIA / GPU stackcurated
Impact
RCE / privesc via input-validation failure
Who can reach it
Unauthenticated client of the inference endpoint
What to do
Upgrade Triton; rebuild and redeploy all serving images
References
Related entries
- Triton Inference Server: Info disclosure / RCE (OOB read in tensor processing)CVE-2026-24213 · Triton Inference ServerHigh
- Triton Inference Server: RCE (integer overflow in model config parsing)CVE-2026-24214 · Triton Inference ServerHigh
- Triton Inference Server: RCE / privesc / data tampering via model-load path traversal (`--model-control explicit`)CVE-2023-31036 · Triton Inference ServerHigh
- Triton Inference Server: concurrent requests trigger a race condition that crashes the server (remote DoS)CVE-2025-33238 · Triton Inference ServerHigh
- Triton Inference Server: DoS via memory exhaustion on malformed inputCVE-2026-24146 · Triton Inference ServerHigh
- Triton Inference Server: Arbitrary file access via unsafe path operationsCVE-2026-24209 · Triton Inference ServerHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.