CVE-2025-23316

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause a remote code execution by manipulating the model name parameter in the model control APIs. A successful exploit of this vulnerability might lead to remote code execution, denial of service, information disclosure, and data tampering.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

17 Jun 2026, 08:53

Type Values Removed Values Added
Summary
  • (es) NVIDIA Triton Inference Server para Windows y Linux contiene una vulnerabilidad en el backend de Python, donde un atacante podría causar una ejecución remota de código manipulando el parámetro del nombre del modelo en las API de control del modelo. Un exploit exitoso de esta vulnerabilidad podría conducir a ejecución remota de código, denegación de servicio, revelación de información y manipulación de datos.

25 Sep 2025, 20:20

Type Values Removed Values Added
First Time Microsoft
Nvidia
Nvidia triton Inference Server
Linux
Microsoft windows
Linux linux Kernel
CPE cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5691 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5691 - Vendor Advisory

17 Sep 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-17 22:15

Updated : 2026-06-17 08:53


NVD link : CVE-2025-23316

Mitre link : CVE-2025-23316

CVE.ORG link : CVE-2025-23316


JSON object : View

Products Affected

nvidia

  • triton_inference_server

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')