NVIDIA patched multiple critical vulnerabilities in Triton Inference Server that can let remote, unauthenticated attackers crash or fully compromise AI inference servers exposed over HTTP. The issues affect Triton versions prior to 25.07 on Linux and Windows and include stack and heap memory corruption flaws such as CVE-2025-23310, CVE-2025-23311, CVE-2025-23317, CVE-2025-23318, and the related Python-backend chain CVE-2025-23319, CVE-2025-23320, and CVE-2025-23334. Several bugs stem from unsafe HTTP request parsing and chunked transfer handling, while others arise from improper validation in Triton’s shared memory and Python backend components, creating paths to denial of service, information disclosure, data tampering, and remote code execution.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
NVIDIA released patched driver versions for affected R580, R570, and R535 branches to address the October 2025 display driver vulnerabilities. The fixes included versions 580.95.05, 570.195.03, and 535.274.02 for Linux issues and corresponding patched releases for the DLL hijacking flaw.
NVIDIA disclosed multiple display driver vulnerabilities in its October 2025 security bulletin, including CVE-2025-23280, CVE-2025-23282, and CVE-2025-23309. The bulletin covered Linux and cross-platform driver issues affecting several supported branches.
ZeroPath reports that researchers identified CVE-2025-23311, a critical stack-based buffer overflow in Triton HTTP request handling, through static analysis and manual review. The flaw had reportedly existed in the codebase for more than five years before being fixed in version 25.07.
ZeroPath reports that CVE-2025-23310, a critical Triton stack buffer overflow in HTTP chunked request handling, was discovered by Will Vandevanter of Trail of Bits. The flaw affected Triton versions prior to 25.07 on Windows and Linux.
Researchers publicly described a critical Triton attack chain involving CVE-2025-23319, CVE-2025-23320, and CVE-2025-23334 that could enable unauthenticated remote code execution and full server compromise. The disclosure explained that verbose error messages could leak an internal shared memory region name that attackers could then abuse through legitimate APIs.
NVIDIA released a patch for the Triton Inference Server vulnerabilities on August 4, 2025, according to Infosecurity Magazine. The fixes were delivered in Triton Inference Server version 25.07 and addressed multiple critical issues affecting the HTTP server and Python backend.
NVIDIA patched the high-severity improper index validation flaw CVE-2025-23278 in its July 2025 GPU display driver security update. The fixes were released across multiple driver branches, including versions 575.64.05, 570.172.08, and 535.261.03.
Python addressed CVE-2025-8194 in cpython PR 137027 by adding validation that rejects tar archive members with negative offsets and raises a ReadError. The change fixed a denial-of-service issue in the standard-library tarfile module.
NVIDIA acknowledged Wiz's report about the Triton Inference Server vulnerability chain on May 16, 2025, according to Infosecurity Magazine. This marked the vendor's formal receipt of the disclosure.
Infosecurity Magazine reports that Wiz disclosed a chain of critical NVIDIA Triton Inference Server vulnerabilities to NVIDIA on May 15, 2025. The issues were later assigned CVE-2025-23319, CVE-2025-23320, and CVE-2025-23334.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
zeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourceinfosecurity-magazine.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.