Description
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service.
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA Triton Inference Server for Linux suffers a resource exhaustion flaw that allows an attacker to trigger unbounded allocation of system resources. The failure can lead to denial of service by exhausting memory or CPU, preventing legitimate users from accessing the service. This weakness falls under CWE-770, the category of Resource Exhaustion.

Affected Systems

Affected are NVIDIA Triton Inference Server installations running on Linux platforms. Specific affected versions are not enumerated in the available data.

Risk and Exploitability

The CVSS score of 7.5 signals a high severity vulnerability. EPSS data is unavailable, so the probability of exploitation is unknown, though the absence from the CISA KEV catalog suggests no confirmed public exploits yet. The likely attack vector is remote, via crafted inference requests sent to the server; a successful exploit would disrupt availability for all users without providing privilege escalation or data disclosure.

Generated by OpenCVE AI on August 18, 2026 at 19:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest NVIDIA Triton Inference Server patch that addresses the unbounded resource allocation flaw.
  • Configure operating‑system or container limits to cap memory and CPU usage for the Triton process, thereby reducing the impact of a resource exhaustion event.
  • Continuously monitor Triton’s resource utilization and implement alerting for abnormal spikes that could indicate an ongoing exploitation attempt.

Generated by OpenCVE AI on August 18, 2026 at 19:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unbounded Resource Allocation Exploit in NVIDIA Triton Inference Server

Tue, 18 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia triton Inference Server
Vendors & Products Nvidia
Nvidia triton Inference Server

Tue, 18 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service.
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Nvidia Triton Inference Server
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-18T18:45:52.834Z

Reserved: 2026-05-19T19:55:52.529Z

Link: CVE-2026-47628

cve-icon Vulnrichment

Updated: 2026-08-18T18:45:49.587Z

cve-icon NVD

Status : Received

Published: 2026-08-18T19:16:51.740

Modified: 2026-08-18T19:16:51.740

Link: CVE-2026-47628

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T19:45:03Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling