NVIDIA Triton Inference Server Out-of-Bounds Write Vulnerability in Python Backend

Vulnerability

A vulnerability exists in the Python backend of NVIDIA Triton Inference Server for Windows and Linux, where an attacker could trigger an out-of-bounds write. Exploitation of this vulnerability may result in code execution, denial of service, data tampering, and information disclosure. The issue affects all versions prior to 25.07.

Impact

Successful exploitation could lead to code execution, denial of service, data tampering, and information disclosure.

Remediation

Users are advised to update to version 25.07 or later. Instructions for downloading the latest version are available on the NVIDIA Triton Inference Server Releases page on GitHub.

Added: Aug 6, 2025, 1:26 PM
Updated: Aug 6, 2025, 1:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.