Database/AI/ML frameworks & serving
NVIDIA Triton (Python backend): Information disclosure from the Python backend
CVSS 7.5CVE-2025-23320AI/ML frameworks & servingcurated
Impact
Information disclosure from the Python backend
Who can reach it
Unauthenticated network
What to do
Patch; leaks the shared-memory key that enables the write primitive
References
Related entries
- NVIDIA Triton (Python backend): Out-of-bounds write in the Python backendCVE-2025-23318 · NVIDIA Triton (Python backend)High
- vLLM (weight loading): `hf_model_weights_iterator` uses `torch.load` without `weights_only`CVE-2025-24357 · vLLM (weight loading)High
- vLLM (ZeroMQ): DoS and data exposure over ZeroMQCVE-2025-30202 · vLLM (ZeroMQ)High
- vLLM (HTTP GET): Single HTTP GET crashes the serverCVE-2025-48956 · vLLM (HTTP GET)High
- PyTorch (`torch.linalg.lu`): DoS on slice operationCVE-2025-55551 · PyTorch (`torch.linalg.lu`)High
- PyTorch (KV/conv path buffer overflow): Buffer overflow when a model combines Conv2d + hardshrink + viewCVE-2025-55558 · PyTorch (KV/conv path buffer overflow)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.