NVIDIA AIStore: Missing authentication on API endpoints
CVSS 9.8CVE-2026-24270NVIDIA / GPU stackcurated
Impact
Missing authentication on API endpoints -> full object-store access
Who can reach it
Network-adjacent unauthenticated inside the cluster
What to do
Emergency upgrade of AIStore; enforce authn + network policy; audit stored tenant data
References
Related entries
- NVIDIA Triton Inference Server: A path traversal scored 9.8 (network, no privileges, fullCVE-2026-47627 · NVIDIA Triton Inference ServerCritical
- NVIDIA GEN3C (Spatial Intelligence Lab) inference API server: The inference API server runs Python pickle.loads()CVE-2026-53805 · NVIDIA GEN3C (Spatial Intelligence Lab) inference API serverCritical
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: An attacker with privileged access reachesCVE-2025-33187 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareCritical
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): Memory is handed to a consumer without being initialisedCVE-2021-47348 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)Critical
- Triton Inference Server: RCE via path traversal on the model-load APICVE-2024-0087 · Triton Inference ServerCritical
- Triton Inference Server: Improper logging of security events (audit gap)CVE-2024-0095 · Triton Inference ServerCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.