PT-2025-31845 · Nvidia · Nvidia Triton Inference Server

Ronen Shustin

·

Published

2025-08-04

·

Updated

2025-08-23

·

CVE-2025-23319

CVSS v3.1
9.8
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions**

NVIDIA Triton Inference Server versions prior to 25.07

**Description**

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend that allows an attacker to cause an out-of-bounds write by sending a specially crafted request. Successful exploitation of this vulnerability may lead to remote code execution, denial of service, data tampering, or information disclosure. The vulnerability chain allows unauthenticated attackers to gain full control of the server.

**Recommendations**

Upgrade to version 25.07 or higher.

Fix

RCE

DoS

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-09443
CVE-2025-23319

Affected Products

Nvidia Triton Inference Server