Description
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
Published: 2026-07-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a server-side request forgery in NVIDIA TensorRT-LLM’s multimodal media fetching functions. This flaw allows an attacker who can reach the service over the network to compel the server to make HTTP requests to arbitrary destinations. If successfully exploited, the server could become overloaded, resulting in denial of service, or it could retrieve and expose sensitive information.

Affected Systems

NVIDIA TensorRT-LLM running on Linux is affected, as noted by the vendor’s identifiers. No specific versions are listed, so all installations of TensorRT-LLM remain potentially vulnerable until a patch is applied or a more restrictive configuration is enforced.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate to high severity, confirming that the flaw allows remote exploitation. The EPSS score below 1% suggests that, while the flaw exists, the overall likelihood of real-world exploitation is low; however, the fact that it can lead to denial of service and information disclosure is a concern. The flaw is not currently listed in CISA’s KEV catalog, but it represents a notable vector for attackers seeking SSRF payloads. The attack would require the attacker to send a crafted request to the TensorRT-LLM service from outside the trusted network, a path that is easily available in many production deployments.

Generated by OpenCVE AI on August 1, 2026 at 09:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade NVIDIA TensorRT-LLM as soon as a patch becomes available
  • Restrict network access to TensorRT-LLM so that only trusted internal hosts can reach its endpoints
  • Configure firewalls or proxies to deny outbound traffic to untrusted domains to mitigate SSRF attempts

Generated by OpenCVE AI on August 1, 2026 at 09:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title SSRF vulnerability in NVIDIA TensorRT-LLM multimodal media fetching

Tue, 28 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title SSRF vulnerability in NVIDIA TensorRT-LLM multimodal media fetching

Sat, 25 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery in NVIDIA TensorRT-LLM Leading to Denial of Service and Information Disclosure

Wed, 22 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery in NVIDIA TensorRT-LLM Leading to Denial of Service and Information Disclosure

Mon, 20 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery in NVIDIA TensorRT‑LLM Multimodal Media Fetching Leading to DoS and Information Disclosure

Thu, 16 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery in NVIDIA TensorRT‑LLM Multimodal Media Fetching Leading to DoS and Information Disclosure

Wed, 15 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia tensorrt-llm
Vendors & Products Nvidia
Nvidia tensorrt-llm

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Nvidia Tensorrt-llm
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-07-15T14:45:03.236Z

Reserved: 2026-01-21T19:09:37.973Z

Link: CVE-2026-24234

cve-icon Vulnrichment

Updated: 2026-07-15T14:44:57.609Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:30:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)