Tools AI Risk Radar ai-incident-0090
Incident record
Two Triton Inference Server flaws let unauthenticated callers exhaust compute or reach unguarded functions
- Severity
- High
- Status
- Patched
- Type
- Infra Vuln
- Target
- NVIDIA Triton Inference Server for Linux through 26.06
- Actor
- researcher
- CVE
- CVE-2026-16497
What happened
An excessive-iteration flaw lets a remote, unauthenticated attacker send malformed input that exhausts compute, and a missing-authorization flaw exposes functions with no access check, risking information disclosure, data tampering and denial of service. Both score CVSS 3.1 7.5 and both are fixed in release 26.07.
The companion record is CVE-2026-47625. NVD carries both with NVIDIA PSIRT as the source; the affected ranges are Triton through 26.06 and through 26.03 respectively.
Sources
- NVD record CVE-2026-16497nvd.nist.gov/vuln/detail/CVE-2026-16497
- NVD record CVE-2026-47625nvd.nist.gov/vuln/detail/CVE-2026-47625
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026