Triton Inference Server: concurrent requests trigger a race condition that crashes the server (remote DoS)
Impact
An unauthenticated client that can reach a Triton endpoint can send concurrent requests that trip a race in request handling and take the server process down, killing every model co-resident on that tier until the pod restarts. NVIDIA split this across 2 CVE ids (CVE-2025-33238, CVE-2025-33254) in bulletin 5790; they are one issue for operational purposes.
Who can reach it
Network-adjacent unauthenticated client
What to do
Roll to the fixed Triton container image per NVIDIA bulletin 5790 - an ordinary rolling deployment restart, no driver, firmware or node change. Pair with an audit of which Triton endpoints are actually reachable, since exposure is what makes this exploitable.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- Triton Inference Server: DoS via memory exhaustion on malformed inputCVE-2026-24146 · Triton Inference ServerHigh
- Triton Inference Server: Arbitrary file access via unsafe path operationsCVE-2026-24209 · Triton Inference ServerHigh
- Triton Inference Server: DoS / memory corruption (integer overflow in buffer allocation)CVE-2026-24210 · Triton Inference ServerHigh
- Triton Inference Server: DoS via improper exception handlingCVE-2026-24264 · Triton Inference ServerHigh
- Triton Inference Server: DoS via resource exhaustionCVE-2026-47476 · Triton Inference ServerHigh
- Triton Inference Server: DoS via stack overflow in recursive processingCVE-2026-47477 · Triton Inference ServerHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.