
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47478 is a Use of Expired File Descriptor vulnerability in NVIDIA Triton Inference Server for Linux that allows an unauthenticated network attacker to trigger denial of service. It affects all versions from 0.0 through 26.04 of NVIDIA Triton Inference Server on Linux. The vulnerability was disclosed on July 14, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 7.5 (High), assigned by NVIDIA Corporation (GitHub Advisory, CVE Record).
The vulnerability is classified as CWE-910 (Use of Expired File Descriptor), meaning the server accesses or uses a file descriptor after it has already been closed. This class of flaw can lead to undefined behavior, resource corruption, or service crashes when the recycled descriptor is accessed unexpectedly. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it automatable according to CISA's SSVC assessment. No public technical write-ups or proof-of-concept code detailing the specific exploitation mechanics have been published as of the disclosure date (GitHub Advisory, CVE Record).
Successful exploitation of this vulnerability results in a denial of service condition, crashing or making the NVIDIA Triton Inference Server service unavailable. The impact is limited to availability — there is no confidentiality or integrity impact, meaning attackers cannot access or modify data through this vulnerability. Organizations relying on Triton Inference Server for AI/ML inference workloads could experience service interruptions affecting downstream applications and pipelines (GitHub Advisory, CVE Record).
NVIDIA has released a patch addressing this vulnerability; users should update NVIDIA Triton Inference Server to a version beyond 26.04. As an interim measure, organizations should restrict network access to the Triton Inference Server so it is not publicly accessible, limiting exposure to trusted networks or internal services only. Monitoring for unexpected service crashes or restarts of the Triton Inference Server process can help detect exploitation attempts (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."