Database/AI/ML frameworks & serving
NVIDIA Triton: Stack buffer overflow
CVSS 9.8CVE-2025-23310AI/ML frameworks & servingcurated
Impact
Stack buffer overflow → code execution
Who can reach it
Unauthenticated network to the inference port
What to do
Patch; part of the Aug-2025 Triton cluster disclosed by Wiz
References
Related entries
- NVIDIA Triton: Stack overflow via crafted requestCVE-2025-23311 · NVIDIA TritonCritical
- NVIDIA Triton Inference Server (Python backend): Attacker-controlled input in the Python backendCVE-2025-23316 · NVIDIA Triton Inference Server (Python backend)Critical
- BentoML: RCE via insecure deserializationCVE-2025-27520 · BentoMLCritical
- BentoML: Insecure deserialization RCE prior to 1.4.8CVE-2025-32375 · BentoMLCritical
- PyTorch (`torch.load`): RCE via unsafe deserialization even with `weights_only=True`CVE-2025-32434 · PyTorch (`torch.load`)Critical
- vLLM (`PyNcclPipe` KV transfer): RCE via the KV cache transfer integrationCVE-2025-47277 · vLLM (`PyNcclPipe` KV transfer)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.