
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-33238 is a denial-of-service vulnerability in the NVIDIA Triton Inference Server's SageMaker HTTP server component, where an attacker can trigger an unhandled exception to disrupt service availability. It was disclosed by NVIDIA Corporation on March 24, 2026, and affects all versions of Triton Inference Server prior to 26.01. The vulnerability carries a CVSS v3.1 base score of 7.5 (High), assigned by NVIDIA (NVIDIA Advisory, Red Hat CVE).
The root cause is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization, i.e., Race Condition), as assigned by NVIDIA Corporation. The vulnerability exists in the SageMaker HTTP server component of Triton Inference Server, where a race condition can be triggered by a remote attacker to cause an unhandled exception. No authentication, user interaction, or elevated privileges are required to exploit this flaw, making it accessible to any network-reachable attacker. Related attack patterns include CAPEC-26 (Leveraging Race Conditions) and CAPEC-29 (TOCTOU Race Conditions) (NVIDIA Advisory, Red Hat CVE).
Successful exploitation results in a denial-of-service condition, crashing or disrupting the Triton Inference Server's SageMaker HTTP endpoint. There is no impact on confidentiality or integrity — only availability is affected. Organizations relying on Triton Inference Server for AI/ML inference workloads in SageMaker-integrated environments could experience service outages, potentially disrupting production inference pipelines (NVIDIA Advisory, Red Hat CVE).
NVIDIA has released a patch addressing this vulnerability in Triton Inference Server version 26.01 and later. Users should upgrade to version 26.01 or newer as the primary remediation. No specific configuration-based workarounds have been published by NVIDIA; restricting network access to the SageMaker HTTP server endpoint may reduce exposure until patching is feasible (NVIDIA Advisory, NVIDIA Product Security).
Security news outlets including GBHackers, CyberPress, and CyberSecurityNews covered CVE-2025-33238 as part of broader reporting on a batch of NVIDIA vulnerabilities enabling RCE and DoS attacks disclosed in March 2026. Coverage generally highlighted the risk to AI/ML infrastructure and the importance of patching Triton Inference Server deployments (GBHackers, CyberSecurityNews, Security Boulevard).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."