Description
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in NVIDIA Triton Inference Server for Linux allows an attacker to cause uncontrolled resource consumption, which can result in a loss of service availability. The weakness is classified as CWE-400, of proper resource usage controls, and a successful exploit may lead to denial of service.

Affected Systems

The affected product is NVIDIA Triton Inference Server running on Linux. No specific version information is provided, indicating that all deployed instances without the described fix may be vulnerable.

Risk and Exploitability

The CVSS score of 7.5 signifies a high severity, while the EPSS score of less than 1% indicates a low probability of exploitation at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is not explicitly stated in the description; however, it is inferred that any actor with the ability to submit or trigger inference requests could potentially trigger resource exhaustion. Accordingly, the threat remains primarily a denial-of-service risk rather than a remote code execution or privilege escalation scenario.

Generated by OpenCVE AI on August 1, 2026 at 09:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure Triton to enforce strict CPU and memory limits for inference engines
  • Restrict access to the Triton Inference Server to trusted users or network segments only
  • Continuously monitor system resource usage to detect and mitigate abnormal consumption patterns

Generated by OpenCVE AI on August 1, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Uncontrolled Resource Consumption Leading to Denial of Service in NVIDIA Triton Inference Server

Tue, 28 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Uncontrolled Resource Consumption Leading to Denial of Service in NVIDIA Triton Inference Server

Sun, 26 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Uncontrolled Resource Consumption in Triton Inference Server Causes Denial of Service

Wed, 22 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Uncontrolled Resource Consumption in Triton Inference Server Causes Denial of Service

Mon, 20 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Uncontrolled Resource Consumption Leading to Denial of Service in NVIDIA Triton Inference Server on Linux

Thu, 16 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Uncontrolled Resource Consumption Leading to Denial of Service in NVIDIA Triton Inference Server on Linux

Wed, 15 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia triton Inference Server
Vendors & Products Nvidia
Nvidia triton Inference Server

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Nvidia Triton Inference Server
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-07-15T14:07:29.600Z

Reserved: 2026-05-19T19:55:38.728Z

Link: CVE-2026-47476

cve-icon Vulnrichment

Updated: 2026-07-15T14:07:24.467Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:30:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption