Unsafe Deserialization Vulnerability in NVIDIA TRT-LLM for Multiple Platforms
CVE-2025-33255

7.5HIGH

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
20 May 2026

What is CVE-2025-33255?

NVIDIA TRT-LLM for various platforms features a vulnerability in its MPI server, allowing attackers to exploit unsafe deserialization processes. A successful exploit could enable malicious actors to execute arbitrary code, disrupt services, manipulate data, and potentially disclose sensitive information.

Affected Version(s)

TensorRT-LLM All 0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.