{ "document": { "aggregate_severity": { "namespace": "https://www.first.org/cvss/v4.0/specification-document#Qualitative-Severity-Rating-Scale", "text": "CRITICAL" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright \u00a9 2025 NVIDIA Corporation. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "NVIDIA has released a software update for NVIDIA\u00ae Triton Inference Server. 
To protect your system, clone or update this software to Triton Server r26.03 or later from the NVIDIA Triton Inference Server GitHub repo.
", "title": "Summary" }, { "category": "legal_disclaimer", "text": "ALL NVIDIA INFORMATION, DESIGN SPECIFICATIONS, REFERENCE BOARDS, FILES, DRAWINGS, DIAGNOSTICS, LISTS, AND OTHER DOCUMENTS (TOGETHER AND SEPARATELY, \"MATERIALS\") ARE BEING PROVIDED \"AS IS.\" NVIDIA MAKES NO WARRANTIES, EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE WITH RESPECT TO THE MATERIALS, AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OR CONDITION OF TITLE, MERCHANTABILITY, SATISFACTORY QUALITY, FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT, ARE HEREBY EXCLUDED TO THE MAXIMUM EXTENT PERMITTED BY LAW.\n\nInformation is believed to be accurate and reliable at the time it is furnished. However, NVIDIA Corporation assumes no responsibility for the consequences of use of such information or for any infringement of patents or other rights of third parties that may result from its use. No license is granted by implication or otherwise under any patent or patent rights of NVIDIA Corporation. Specifications mentioned in this publication are subject to change without notice. This publication supersedes and replaces all information previously supplied. NVIDIA Corporation products are not authorized for use as critical components in life support devices or systems without express written approval of NVIDIA Corporation.", "title": "Terms of Use" }, { "category": "details", "text": "Refer to Security Updates for the updated versions to install.", "title": "Mitigation Notes" }, { "category": "details", "text": "
", "title": "Bulletin Notes" }, { "category": "details", "text": "TB-12183-007_v01", "title": "Part Number" }, { "category": "details", "text": "1153548", "title": "Product Information Delivery" }, { "category": "details", "text": "23:Triton", "title": "Product Team" }, { "category": "details", "text": "false", "title": "Contains Firmware" } ], "publisher": { "category": "vendor", "contact_details": "https://www.nvidia.com/security/report-vulnerability/", "issuing_authority": "NVIDIA Product Security is responsible for vulnerability handling across all NVIDIA products and services.", "name": "NVIDIA Product Security", "namespace": "https://www.nvidia.com/security" }, "title": "Security Bulletin: NVIDIA Triton Inference Server - May 2026", "tracking": { "current_release_date": "2026-05-19T00:00:00Z", "generator": { "date": "2026-05-19T00:00:00Z", "engine": { "name": "NVIDIA PSIRT", "version": "1.0.0" } }, "id": "5828", "initial_release_date": "2026-05-19T00:00:00Z", "revision_history": [ { "date": "2026-05-19T00:00:00Z", "number": "1.0.0", "summary": "Initial Release" } ], "status": "final", "version": "1.0.0" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_name", "name": "Triton Inference Server", "product": { "name": "Triton Inference Server", "product_id": "linux_triton_inference_server", "product_identification_helper": { "cpe": "cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:*" } } }, { "category": "product_name", "name": "Triton Inference Server", "product": { "name": "Triton Inference Server", "product_id": "dali_backend_triton_inference_server", "product_identification_helper": { "cpe": "cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:*" } } } ], "category": "product_family", "name": "NVIDIA Product Family" }, { "branches": [ { "category": "product_version", "name": "Triton Inference Server", "product": { "name": "All versions prior to r26.03", "product_id": "linux_triton_inference_server_all_versions_prior_to_r26_03", "product_identification_helper": { "cpe": "cpe:2.3:a:nvidia:triton_inference_server:all_versions_prior_to_r26_03:*:*:*:*:*:*:*" } } }, { "category": "product_version", "name": "Triton Inference Server", "product": { "name": "r26.03", "product_id": "linux_triton_inference_server_r26_03", "product_identification_helper": { "cpe": "cpe:2.3:a:nvidia:triton_inference_server:r26_03:*:*:*:*:*:*:*" } } } ], "category": "architecture", "name": "Linux" }, { "branches": [ { "category": "product_version", "name": "Triton Inference Server", "product": { "name": "All versions prior to r26.03", "product_id": "dali_backend_triton_inference_server_all_versions_prior_to_r26_03", "product_identification_helper": { "cpe": "cpe:2.3:a:nvidia:triton_inference_server:all_versions_prior_to_r26_03:*:*:*:*:*:*:*" } } }, { "category": "product_version", "name": "Triton Inference Server", "product": { "name": "r26.03", "product_id": "dali_backend_triton_inference_server_r26_03", "product_identification_helper": { "cpe": "cpe:2.3:a:nvidia:triton_inference_server:r26_03:*:*:*:*:*:*:*" } } } ], "category": "architecture", "name": "DALI Backend" } ], "category": "vendor", "name": "NVIDIA" } ] }, "vulnerabilities": [ { "acknowledgments": [ { "names": [ "deayzl" ] } ], "cve": "CVE-2026-24207", "cwe": { "id": "CWE-288", "name": "Authentication Bypass Using an Alternate Path or Channel" }, "notes": [ { "category": "summary", "text": "NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.", "title": "Vulnerability description" }, { "category": "details", "text": "Escalation of Privileges, Data Tampering, Denial of Service, Information Disclosure, Code Execution", "title": "Impacts" }, { "category": "details", "text": "5887469", "title": "defect" } ], "product_status": { "fixed": [ "linux_triton_inference_server_r26_03" ], "known_affected": [ "linux_triton_inference_server_all_versions_prior_to_r26_03" ] }, "references": [ { "category": "self", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24207" }, { "category": "self", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-24207" } ], "release_date": "2026-05-19T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "linux_triton_inference_server_all_versions_prior_to_r26_03" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-24213", "cwe": { "id": "CWE-125", "name": "Out-of-bounds Read" }, "notes": [ { "category": "summary", "text": "NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, or information disclosure.", "title": "Vulnerability description" }, { "category": "details", "text": "Code Execution, Denial of Service, Information Disclosure, Data Tampering", "title": "Impacts" }, { "category": "details", "text": "5897131", "title": "defect" } ], "product_status": { "fixed": [ "dali_backend_triton_inference_server_r26_03" ], "known_affected": [ "dali_backend_triton_inference_server_all_versions_prior_to_r26_03" ] }, "references": [ { "category": "self", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24213" }, { "category": "self", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-24213" } ], "release_date": "2026-05-19T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "dali_backend_triton_inference_server_all_versions_prior_to_r26_03" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-24214", "cwe": { "id": "CWE-190", "name": "Integer Overflow or Wraparound" }, "notes": [ { "category": "summary", "text": "NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, or denial of service.", "title": "Vulnerability description" }, { "category": "details", "text": "Denial of Service, Code Execution, Data Tampering", "title": "Impacts" }, { "category": "details", "text": "5888797", "title": "defect" } ], "product_status": { "fixed": [ "dali_backend_triton_inference_server_r26_03" ], "known_affected": [ "dali_backend_triton_inference_server_all_versions_prior_to_r26_03" ] }, "references": [ { "category": "self", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24214" }, { "category": "self", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-24214" } ], "release_date": "2026-05-19T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "dali_backend_triton_inference_server_all_versions_prior_to_r26_03" ] } ] }, { "acknowledgments": [ { "names": [ "sarvesh patil" ] } ], "cve": "CVE-2026-24209", "cwe": { "id": "CWE-22", "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" }, "notes": [ { "category": "summary", "text": "NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.", "title": "Vulnerability description" }, { "category": "details", "text": "Denial of Service", "title": "Impacts" }, { "category": "details", "text": "5875405", "title": "defect" } ], "product_status": { "fixed": [ "linux_triton_inference_server_r26_03" ], "known_affected": [ "linux_triton_inference_server_all_versions_prior_to_r26_03" ] }, "references": [ { "category": "self", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24209" }, { "category": "self", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-24209" } ], "release_date": "2026-05-19T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "linux_triton_inference_server_all_versions_prior_to_r26_03" ] } ] }, { "acknowledgments": [ { "names": [ "deayzl" ] } ], "cve": "CVE-2026-24210", "cwe": { "id": "CWE-190", "name": "Integer Overflow or Wraparound" }, "notes": [ { "category": "summary", "text": "NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to denial of service.", "title": "Vulnerability description" }, { "category": "details", "text": "Denial of Service", "title": "Impacts" }, { "category": "details", "text": "5907976", "title": "defect" } ], "product_status": { "fixed": [ "linux_triton_inference_server_r26_03" ], "known_affected": [ "linux_triton_inference_server_all_versions_prior_to_r26_03" ] }, "references": [ { "category": "self", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24210" }, { "category": "self", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-24210" } ], "release_date": "2026-05-19T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "linux_triton_inference_server_all_versions_prior_to_r26_03" ] } ] }, { "acknowledgments": [ { "names": [ "Hyeonjun Ahn (@deayzl)" ] } ], "cve": "CVE-2026-24206", "cwe": { "id": "CWE-288", "name": "Authentication Bypass Using an Alternate Path or Channel" }, "notes": [ { "category": "summary", "text": "NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or information disclosure.", "title": "Vulnerability description" }, { "category": "details", "text": "Escalation of Privileges, Denial of Service, Information Disclosure", "title": "Impacts" }, { "category": "details", "text": "5887537", "title": "defect" } ], "product_status": { "fixed": [ "linux_triton_inference_server_r26_03" ], "known_affected": [ "linux_triton_inference_server_all_versions_prior_to_r26_03" ] }, "references": [ { "category": "self", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24206" }, { "category": "self", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-24206" } ], "release_date": "2026-05-19T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 7.3, "baseSeverity": "HIGH", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "version": "3.1" }, "products": [ "linux_triton_inference_server_all_versions_prior_to_r26_03" ] } ] }, { "acknowledgments": [ { "names": [ "Navtej Kathuria" ] } ], "cve": "CVE-2026-24215", "cwe": { "id": "CWE-400", "name": "Uncontrolled Resource Consumption" }, "notes": [ { "category": "summary", "text": "NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.", "title": "Vulnerability description" }, { "category": "details", "text": "Denial of Service", "title": "Impacts" }, { "category": "details", "text": "5897110", "title": "defect" } ], "product_status": { "fixed": [ "dali_backend_triton_inference_server_r26_03" ], "known_affected": [ "dali_backend_triton_inference_server_all_versions_prior_to_r26_03" ] }, "references": [ { "category": "self", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24215" }, { "category": "self", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-24215" } ], "release_date": "2026-05-19T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 5.7, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "dali_backend_triton_inference_server_all_versions_prior_to_r26_03" ] } ] }, { "acknowledgments": [ { "names": [ "Mohamed Lemine ahmed jidou (mauritaniacoder)" ] } ], "cve": "CVE-2026-24208", "cwe": { "id": "CWE-22", "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" }, "notes": [ { "category": "summary", "text": "NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.", "title": "Vulnerability description" }, { "category": "details", "text": "Denial of Service", "title": "Impacts" }, { "category": "details", "text": "5907723", "title": "defect" } ], "product_status": { "fixed": [ "linux_triton_inference_server_r26_03" ], "known_affected": [ "linux_triton_inference_server_all_versions_prior_to_r26_03" ] }, "references": [ { "category": "self", "summary": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24208" }, { "category": "self", "summary": "Mitre", "url": "https://www.cve.org/CVERecord?id=CVE-2026-24208" } ], "release_date": "2026-05-19T00:00:00Z", "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "linux_triton_inference_server_all_versions_prior_to_r26_03" ] } ] } ] }