Description
NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A successful exploit of this vulnerability might lead to denial of service.
Published: 2026-07-14
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA TensorRT‑LLM contains a CWE‑20 input validation flaw in the gRPC chat API endpoint that can be triggered by a local attacker. Exploiting this flaw may cause the TensorRT‑LLM process to become unavailable, resulting in a denial of service.

Affected Systems

All NVIDIA TensorRT‑LLM implementations on any platform are potentially affected. The specific component is the gRPC chat API endpoint; no version information is disclosed, so all current releases may be vulnerable until an update is released.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate risk. An EPSS score of less than 1 % suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires a local attacker with the ability to send crafted gRPC requests to the TensorRT‑LLM process. The impact is limited to availability; no elevation of privilege or data exposure is reported.

Generated by OpenCVE AI on August 3, 2026 at 03:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade NVIDIA TensorRT‑LLM to the latest release once a vendor patch that addresses gRPC input validation is available.
  • Restrict local access to the TensorRT‑LLM gRPC chat API by configuring host‑based firewall rules or using network segmentation so that only trusted services can reach the endpoint.
  • Disable or remove the chat API endpoint if it is not required, thereby eliminating the attack surface until a vendor fix is released.

Generated by OpenCVE AI on August 3, 2026 at 03:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title CWE-20 Vulnerability in NVIDIA TensorRT‑LLM gRPC Chat API Enables Denial of Service

Wed, 29 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title CWE-20 Vulnerability in NVIDIA TensorRT‑LLM gRPC Chat API Enables Denial of Service

Sat, 25 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via gRPC Input Validation Failure in NVIDIA TensorRT‑LLM

Wed, 22 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via gRPC Input Validation Failure in NVIDIA TensorRT‑LLM

Mon, 20 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via gRPC Input Validation Failure in NVIDIA TensorRT-LLM

Thu, 16 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via gRPC Input Validation Failure in NVIDIA TensorRT-LLM

Wed, 15 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia tensorrt-llm
Vendors & Products Nvidia
Nvidia tensorrt-llm

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A successful exploit of this vulnerability might lead to denial of service.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Nvidia Tensorrt-llm
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-07-15T14:18:56.930Z

Reserved: 2026-05-19T19:55:37.796Z

Link: CVE-2026-47470

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:15:05Z

Weaknesses
  • CWE-20

    Improper Input Validation