NVIDIA AIStore - AuthN: An unauthenticated user extracts information from the AIStore authentication component
CVSS 5.3CVE-2025-33185NVIDIA / GPU stackcurated
Impact
An unauthenticated user extracts information from the AIStore authentication component. AIStore fronts training datasets, so what leaks here is metadata about your data estate.
Who can reach it
Network, unauthenticated, no user interaction. Anyone who can reach the AuthN endpoint.
What to do
Upgrade AIStore per bulletin 5724 and roll the AuthN pods. Cost: rolling restart of the storage control plane; data path is unaffected.
References
Related entries
- NVIDIA AIStore - AuthN: A flaw in the AIStore authentication component reaches privilege escalation, informationCVE-2025-33186 · NVIDIA AIStore - AuthNHigh
- Triton Inference Server: Info disclosure via path traversal on model filesCVE-2026-24208 · Triton Inference ServerMedium
- TensorRT: DoS via resource exhaustionCVE-2026-24227 · TensorRTMedium
- NVIDIA Dynamo: Error messages from Dynamo leak sensitive information to an unauthenticated network callerCVE-2026-47622 · NVIDIA DynamoMedium
- DGX H100 BMC (REST): DoSCVE-2023-31011 · DGX H100 BMC (REST)Medium
- NVIDIA Jetson Linux (initrd, nvluks trusted application): The nvluks trusted application is left enabled after initrdCVE-2026-24153 · NVIDIA Jetson Linux (initrd, nvluks trusted application)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.