Out-of-bounds Write Vulnerability in NVIDIA Triton Inference Server for Windows and Linux
CVE-2025-23318

8.1HIGH

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
6 August 2025

What is CVE-2025-23318?

The NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in its Python backend which allows an attacker to perform an out-of-bounds write. If successfully exploited, this flaw could lead to various serious consequences including unauthorized code execution, potential denial of service, data integrity issues, and unauthorized information exposure. It is crucial for users and organizations utilizing Triton Inference Server to apply necessary patches or mitigations to safeguard against these risks.

Affected Version(s)

Triton Inference Server Windows All versions prior to 25.07

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-23318 : Out-of-bounds Write Vulnerability in NVIDIA Triton Inference Server for Windows and Linux