PT-2025-31845 · Nvidia · Nvidia Triton Inference Server

Published

2025-08-04

·

Updated

2025-08-06

·

CVE-2025-23319

CVSS v3.1
8.1
VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

### Name of the Vulnerable Software and Affected Versions:

NVIDIA Triton Inference Server versions prior to 25.07

### Description:

A vulnerability chain in NVIDIA Triton Inference Server allows remote, unauthenticated attackers to gain full Remote Code Execution (RCE) and potentially take control of the server. The vulnerability involves flaws starting with an information leak within the Python backend. Exploitation can lead to denial-of-service (DoS) or data theft via crafted requests. The server is a cornerstone of many AI/ML production environments.

### Recommendations:

Upgrade to version 25.07 or higher.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-23319

Affected Products

Nvidia Triton Inference Server