logo

Breaking NVIDIA Triton: CVE-2025-23319 - A Vulnerability Chain Leading to AI Server Takeover

ID: ea4c2fbb-64d7-5792-b003-a84690d517a0

STIX ID: report--ea4c2fbb-64d7-5792-b003-a84690d517a0

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2025-08-04

Date Updated: 2026-05-01

...
...

Wiz Research disclosed a chain of critical vulnerabilities in NVIDIA Triton Inference Server's Python backend that allow an attacker to obtain the backend's internal shared memory name via an error message, register that internal shared memory through the public shared-memory API to gain arbitrary read/write into backend memory, and ultimately achieve remote code execution and full server compromise; NVIDIA assigned CVE-2025-23319, CVE-2025-23320, and CVE-2025-23334 and released patches, with users advised to update to version 25.07.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.