CVE-2026-47478
Deferred Deferred - Pending Action

Use-After-Free in NVIDIA Triton Inference Server

Vulnerability report for CVE-2026-47478, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-15

Assigner: NVIDIA Corporation

Description

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of this vulnerability might lead to denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-15
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
nvidia triton_inference_server *
nvidia triton_inference_server to 26.04 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-910 The product uses or accesses a file descriptor after it has been closed.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

NVIDIA Triton Inference Server for Linux has a flaw where an attacker can exploit an expired file descriptor. This causes the server to use a resource it should no longer have access to, potentially leading to a denial of service where the system becomes unavailable.

Detection Guidance

Detection of CVE-2026-47478 requires checking the version of NVIDIA Triton Inference Server running on your system. If the version is 0.0 up to and including 26.04, the system is vulnerable. Use commands like 'docker ps' (if running in containers) or 'dpkg -l | grep triton' (for Debian-based systems) to identify installed versions.

Impact Analysis

If you use NVIDIA Triton Inference Server for Linux versions up to 26.04, an attacker could exploit this to crash the server, making it unavailable for legitimate users. This disrupts services relying on the server for tasks like AI inference.

Compliance Impact

The provided CVE data does not specify direct impacts on compliance with standards like GDPR or HIPAA. The vulnerability primarily causes denial of service through expired file descriptors, which may disrupt services but lacks explicit compliance implications in the given context.

Mitigation Strategies

Update NVIDIA Triton Inference Server for Linux to a version beyond 26.04 to address the expired file descriptor vulnerability. Monitor NVIDIA's official security advisories for patches and apply them promptly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47478. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart