Description
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service.
Published: 2026-09-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker could cause the Triton Inference Server to perform excessive iterations, exhausting resources and preventing normal operation. The flaw is a resource exhaustion vulnerability, classified as CWE‑834. The description does not specify attack details, but the nature of the issue implies that malformed inference requests or a malicious client interacting with the inference service could trigger the excessive processing.

Affected Systems

The vulnerability affects NVIDIA Triton Inference Server for Linux installations. No specific product versions were listed, so any deployment of this server could be susceptible.

Risk and Exploitability

The CVSS score of 7.5 signals a high severity and indicates that, once exploited, the server could become unavailable to legitimate users. While the EPSS score is not available, the flaw is not listed in the CISA KEV catalog, suggesting no publicly known exploitation yet. The likely attack vector is an external or local client connecting to the inference API and sending crafted requests; the exploitability hinges on the ability to reach the server and provide input that triggers the resource consumption.

Generated by OpenCVE AI on September 8, 2026 at 18:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Triton to the latest release that contains the resource exhaustion fix, as distributed by NVIDIA
  • If a patch is not immediately available, implement rate limiting or resource quotas on the inference endpoints to curb excessive request processing
  • Enforce monitoring for abnormal CPU or memory usage and block or throttle IPs exhibiting sustained high iteration patterns

Generated by OpenCVE AI on September 8, 2026 at 18:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia triton Inference Server
Vendors & Products Nvidia
Nvidia triton Inference Server

Tue, 08 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Resource Exhaustion Vulnerability Allowing Denial of Service in NVIDIA Triton Inference Server

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service.
Weaknesses CWE-834
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Nvidia Triton Inference Server
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-08T18:03:39.875Z

Reserved: 2026-07-21T17:05:13.737Z

Link: CVE-2026-16497

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T17:17:32.910

Modified: 2026-09-08T19:17:51.043

Link: CVE-2026-16497

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:30:04Z

Weaknesses