CVE-2026-47480
Triton Inference Server vulnerability analysis and mitigation

Overview

CVE-2026-47480 is an uncaught exception vulnerability in NVIDIA Triton Inference Server for Linux that allows a remote, unauthenticated attacker to trigger a denial of service condition. It affects all versions of Triton Inference Server from 0.0 through 26.04 (inclusive). The CVE was received from NVIDIA Corporation on July 14, 2026, and assigned a CVSS v3.1 base score of 7.5 (High) by NVIDIA (CVE Record).

Technical details

The vulnerability is classified as CWE-248 (Uncaught Exception), meaning the application fails to properly handle or catch an exception condition that an attacker can deliberately trigger. Because the attack vector is network-accessible, requires no privileges, no user interaction, and has low attack complexity, the flaw can be exploited remotely by sending crafted requests to the Triton Inference Server that induce an unhandled exception, causing the server process to crash or become unavailable. No detailed technical write-up or public proof-of-concept code has been published at this time (CVE Record).

Impact

Successful exploitation results in a denial of service against the affected Triton Inference Server instance, with high availability impact and no confidentiality or integrity impact. Because Triton Inference Server is commonly used to serve AI/ML inference workloads in production environments, an outage could disrupt dependent applications and services. The scope is limited to the affected server instance, with no evidence of lateral movement or data exposure risk based on currently available information (CVE Record).

Mitigation and workarounds

NVIDIA has identified all Triton Inference Server versions from 0.0 through 26.04 as affected. Users should monitor the official NVIDIA Product Security page for a patched release and apply updates as soon as they become available. In the interim, organizations should restrict network access to Triton Inference Server endpoints using firewalls or network segmentation, limiting exposure to trusted clients only. No specific workaround has been publicly documented by NVIDIA at this time (CVE Record).

Additional resources


SourceThis report was generated using AI

Related Triton Inference Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47482HIGH7.5
  • Triton Inference Server logoTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoNoJul 14, 2026
CVE-2026-47480HIGH7.5
  • Triton Inference Server logoTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoNoJul 14, 2026
CVE-2026-47479HIGH7.5
  • Triton Inference Server logoTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoNoJul 14, 2026
CVE-2026-47478HIGH7.5
  • Triton Inference Server logoTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoNoJul 14, 2026
CVE-2026-47481MEDIUM6.5
  • Triton Inference Server logoTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoNoJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management