Impact
NVIDIA TensorRT‑LLM contains a CWE‑20 input validation flaw in the gRPC chat API endpoint that can be triggered by a local attacker. Exploiting this flaw may cause the TensorRT‑LLM process to become unavailable, resulting in a denial of service.
Affected Systems
All NVIDIA TensorRT‑LLM implementations on any platform are potentially affected. The specific component is the gRPC chat API endpoint; no version information is disclosed, so all current releases may be vulnerable until an update is released.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate risk. An EPSS score of less than 1 % suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires a local attacker with the ability to send crafted gRPC requests to the TensorRT‑LLM process. The impact is limited to availability; no elevation of privilege or data exposure is reported.
OpenCVE Enrichment