NVIDIA Triton Inference Server DALI Backend Improper Input Validation Vulnerability Leading to Code Execution

Vulnerability

A vulnerability exists in the DALI backend of NVIDIA Triton Inference Server, where improper input validation may allow an attacker to execute code. This issue affects all versions prior to 25.07.

Impact

Exploitation of this vulnerability could result in unauthorized code execution on the server.

Remediation

Users are advised to update to version 25.07 or later. For those deploying Triton Inference Server in production, consult the Secure Deployment Considerations Guide to ensure proper logging and shared memory API protections.

Added: Sep 17, 2025, 10:18 PM
Updated: Sep 17, 2025, 10:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.8
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.