Description
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA Triton Inference Server for Linux contains a flaw that allows an attacker to cause uncontrolled resource consumption, which may lead to a denial of service. The weakness is identified as CWE-400 and permits the attacker to exhaust available memory or CPU.

Affected Systems

The vulnerability affects NVIDIA Triton Inference Server running on Linux platforms. No specific version information is provided in the available data, so the issue may exist in multiple or all released versions of the product.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, but the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is not explicitly stated; it is inferred that a remote attacker could network, assuming no additional access controls prevent it.

Generated by OpenCVE AI on July 31, 2026 at 05:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update NVIDIA Triton Inference Server to the latest release containing the fix; restrict the number of concurrent inference requests (e.g., by applying connection limits or rate‑limiting mechanisms) to reduce the risk of resource depletion.
  • Continuously monitor server resource utilization and set alerts for abnormal memory or CPU consumption so that any attempt to exploit the flaw can be detected early.
  • Configure operating‑system resource limits such as cgroups, ulimit, or container quotas to constrain the maximum memory and CPU available to each inference process, preventing a single request from exhausting all resources.

Generated by OpenCVE AI on July 31, 2026 at 05:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Uncontrolled Resource Consumption in NVIDIA Triton Inference Server

Tue, 28 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Resource Exhaustion Exploit in NVIDIA Triton Inference Server

Wed, 22 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Resource Exhaustion Exploit in NVIDIA Triton Inference Server

Fri, 17 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Uncontrolled Resource Consumption in NVIDIA Triton Inference Server Leading to Possible Denial of Service

Thu, 16 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Uncontrolled Resource Consumption in NVIDIA Triton Inference Server Leading to Possible Denial of Service

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia triton Inference Server
Vendors & Products Nvidia
Nvidia triton Inference Server

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Nvidia Triton Inference Server
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-07-15T14:36:59.344Z

Reserved: 2026-05-19T19:55:38.728Z

Link: CVE-2026-47479

cve-icon Vulnrichment

Updated: 2026-07-15T14:36:55.632Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:15:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption