NVIDIA TensorRT-LLM Deserialization Vulnerability Leading to Code Execution

Vulnerability

A deserialization vulnerability has been identified in NVIDIA TensorRT-LLM, affecting all platforms and versions prior to 1.2. This vulnerability involves unsafe handling of serialized data, which could be exploited to execute arbitrary code, tamper with data, or disclose sensitive information.

Impact

Exploitation of this vulnerability could result in unauthorized code execution, data manipulation, and leakage of confidential information.

Added: May 20, 2026, 4:25 AM
Updated: May 20, 2026, 4:25 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.1
remediation
0.0
relevance
8.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.