NVIDIA Triton Inference Server: An absolute path traversal reaches code execution and information disclosure
Impact
An absolute path traversal reaches code execution and information disclosure - the attacker reads or writes outside the model repository. On a shared inference tier this is a noisy-neighbour weapon: one tenant's request kills the server process and takes every co-resident model with it, and the GPU sits idle until the pod restarts.
Who can reach it
Network. Anyone who can reach the Triton HTTP or gRPC endpoint. In most clusters that is anything on the pod network; where ingress is loosely scoped it is the internet. No authentication step exists in Triton itself to stop it.
What to do
Roll to the fixed Triton container image per bulletin 5865. Cost: an ordinary rolling deployment restart - no driver, firmware or node change. Worth pairing with an audit of Triton endpoint exposure, since almost every bug in this component is only interesting because the endpoint is reachable.
References
Related entries
- NVIDIA Triton Inference Server: Manipulating the Python backend's shared memory region produces an out-of-bounds readCVE-2025-23333 · NVIDIA Triton Inference ServerMedium
- NVIDIA Triton Inference Server: A crafted request causes an out-of-bounds read in the Python backend, disclosing memoryCVE-2025-23334 · NVIDIA Triton Inference ServerMedium
- NVIDIA Triton Inference Server: An absolute path traversal reachable from a local low-privileged account reaches codeCVE-2026-47630 · NVIDIA Triton Inference ServerMedium
- NVIDIA Triton Inference Server: An out-of-bounds read triggered by releasing a shared memory region while it is stillCVE-2024-0116 · NVIDIA Triton Inference ServerMedium
- NVIDIA Triton Inference Server: A specific model configuration plus a specific input causes an underflowCVE-2025-23335 · NVIDIA Triton Inference ServerMedium
- NVIDIA Triton Inference Server: Loading a misconfigured model causes a denial of serviceCVE-2025-23336 · NVIDIA Triton Inference ServerMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.