TL;DR

A critical vulnerability in NVIDIA Triton Inference Server's EVBufferToJson function allows remote attackers to trigger a DoS condition, rated CVSS 7.5.

What happened

['NVIDIA Triton Inference Server exposed to unauthenticated DoS attacks']

Why it matters for ops

['EVBufferToJson function flaw triggers exception causing service disruption', 'Impact on inference workloads without authentication required']

Mitigation

  • Upgrade to the latest version of Triton
  • Apply patches from NVIDIA addressing CVE-2025-33201

Action items

  • Verify system configurations for Triton dependencies
  • Check for updates and apply security patches immediately

Detection IOCs

  • Unexpected shutdowns of Triton server instances
  • Increased CPU and memory usage before crashes

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-061/