YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0090

Incident record

Two Triton Inference Server flaws let unauthenticated callers exhaust compute or reach unguarded functions

Severity
High
Status
Patched
Type
Infra Vuln
Target
NVIDIA Triton Inference Server for Linux through 26.06
Actor
researcher
CVE
CVE-2026-16497

What happened

An excessive-iteration flaw lets a remote, unauthenticated attacker send malformed input that exhausts compute, and a missing-authorization flaw exposes functions with no access check, risking information disclosure, data tampering and denial of service. Both score CVSS 3.1 7.5 and both are fixed in release 26.07.

The companion record is CVE-2026-47625. NVD carries both with NVIDIA PSIRT as the source; the affected ranges are Triton through 26.06 and through 26.03 respectively.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026