Description
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service.
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow (CWE-121) that allows an attacker to trigger a denial of service in NVIDIA Triton Inference Server for Linux. A successful exploit would overwrite return addresses on the stack, causing the process to crash and rendering the inference service unavailable. The impact is loss of availability, affecting any applications that rely on continuous model inference.

Affected Systems

NVIDIA Triton Inference Server for Linux is the affected product. Vendor and product information is provided, but the data does not list specific versions; therefore all deployed versions may be impacted until a patched release is available.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity potential. The EPSS score of less than 1% suggests that, as of now, exploitation probability is very low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, where an attacker sends specially crafted requests to the inference endpoints to trigger the buffer overflow. If exploited, the denial of service could affect service continuity and potentially cascade to dependent systems in a deployment network.

Generated by OpenCVE AI on August 1, 2026 at 09:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official vendor patch or upgraded package when it becomes available.
  • Configure firewall rules or access controls so that only trusted IP addresses can reach health‑check and auto‑restart mechanisms to quickly recover the service if it crashes, and monitor logs for anomalous stack overflows or crashes.
  • Deploy a redundant inference server instance or load balancer to maintain service availability during a crash, reducing the impact of a denial‑of‑service attack.

Generated by OpenCVE AI on August 1, 2026 at 09:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Stack-Based Buffer Overflow Causing Denial of Service in NVIDIA Triton Inference Server

Tue, 28 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Stack-Based Buffer Overflow Causing Denial of Service in NVIDIA Triton Inference Server

Wed, 22 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Stack-Based Buffer Overflow in NVIDIA Triton Inference Server Leading to Denial of Service

Fri, 17 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Stack-Based Buffer Overflow in NVIDIA Triton Inference Server Leading to Denial of Service

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia triton Inference Server
Vendors & Products Nvidia
Nvidia triton Inference Server

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service.
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Nvidia Triton Inference Server
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-07-15T14:08:01.204Z

Reserved: 2026-05-19T19:55:38.728Z

Link: CVE-2026-47477

cve-icon Vulnrichment

Updated: 2026-07-15T14:07:57.798Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:30:03Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow