Inference infrastructure
Servers, runtimes and accelerators that host models, such as inference servers, GPU drivers and serving frameworks.
- All items
- 222
- Last 90 days
- 80
- Change
- +100%vs 40 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 9 |
| Jun 2025 | 0 |
| Jul 2025 | 1 |
| Aug 2025 | 19 |
| Sep 2025 | 5 |
| Oct 2025 | 2 |
| Nov 2025 | 4 |
| Dec 2025 | 3 |
| Jan 2026 | 7 |
| Feb 2026 | 3 |
| Mar 2026 | 5 |
| Apr 2026 | 14 |
| May 2026 | 18 |
| Jun 2026 | 12 |
| Jul 2026 | 20 |
| Aug 2026 | 18 |
| Sep 2026 | 36 |
| Oct 2026 | 12 |
222 items
CVE-2025-44779: Ollama arbitrary file deletion via crafted packet to /api/pull
Aug 7, 2025MediumVulnerabilitySecurityCVE-2025-44779CVE-2025-44779 affects Ollama v0.1.33. According to the source, an attacker can delete arbitrary files by sending a crafted packet to the endpoint /api/pull. The NVD has not yet provided an assessment, and the CWE mappings are CWE-20 (Improper Input Validation) and CWE-552 (Files or Directories Accessible to External Parties).
NVD/CVE DatabaseCVE-2025-23335: NVIDIA Triton Inference Server integer underflow via model configuration
Aug 6, 2025MediumVulnerabilitySecurityCVE-2025-23335NVIDIA Triton Inference Server for Windows and Linux and the Tensor RT backend contain an integer underflow (CWE-191) that an attacker can trigger with a specific model configuration and a specific input. A successful exploit might lead to denial of service. NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2025-23334: NVIDIA Triton Inference Server Python backend out-of-bounds read
Aug 6, 2025MediumVulnerabilitySecurityCVE-2025-23334NVIDIA Triton Inference Server for Windows and Linux contains an out-of-bounds read in its Python backend (CWE-125), tracked as CVE-2025-23334. An attacker can trigger it by sending a request, and a successful exploit might lead to information disclosure. NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2025-23333: NVIDIA Triton Inference Server out-of-bounds read via shared memory
Aug 6, 2025MediumVulnerabilitySecurityCVE-2025-23333NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, tracked as CVE-2025-23333 and classified as CWE-125 (Out-of-bounds Read). An attacker could manipulate shared memory data to cause an out-of-bounds read, and a successful exploit might lead to information disclosure. NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2025-23331: NVIDIA Triton Inference Server memory allocation flaw via invalid request
Aug 6, 2025HighVulnerabilitySecurityCVE-2025-23331CVE-2025-23331 affects NVIDIA Triton Inference Server for Windows and Linux. A user who sends an invalid request can cause a memory allocation with an excessive size value, leading to a segmentation fault. A successful exploit might lead to denial of service.
NVD/CVE DatabaseCVE-2025-23327: NVIDIA Triton Inference Server integer overflow via crafted inputs
Aug 6, 2025HighVulnerabilitySecurityCVE-2025-23327NVIDIA Triton Inference Server for Windows and Linux contains an integer overflow vulnerability (CWE-190) that an attacker can trigger through specially crafted inputs. A successful exploit might lead to denial of service and data tampering. The NVD assessment is not yet provided, and no affected versions are listed in the source.
NVD/CVE DatabaseCVE-2025-23326: NVIDIA Triton Inference Server integer overflow via crafted input
Aug 6, 2025HighVulnerabilitySecurityCVE-2025-23326NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability, CVE-2025-23326, where an attacker could cause an integer overflow through a specially crafted input. A successful exploit might lead to denial of service. The NVD assessment is not yet provided.
NVD/CVE DatabaseCVE-2025-23325: NVIDIA Triton Inference Server uncontrolled recursion via crafted input
Aug 6, 2025HighVulnerabilitySecurityCVE-2025-23325NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability (CWE-674, Uncontrolled Recursion) where an attacker can trigger uncontrolled recursion through a specially crafted input. A successful exploit might lead to denial of service. NVD has not yet provided an assessment, and the source does not list affected versions.
NVD/CVE DatabaseCVE-2025-23324: NVIDIA Triton Inference Server integer overflow via invalid request
Aug 6, 2025HighVulnerabilitySecurityCVE-2025-23324CVE-2025-23324 affects NVIDIA Triton Inference Server for Windows and Linux. A user who sends an invalid request can cause an integer overflow or wraparound (CWE-190), leading to a segmentation fault. A successful exploit might lead to denial of service.
NVD/CVE DatabaseCVE-2025-23323: NVIDIA Triton Inference Server integer overflow from invalid request
Aug 6, 2025HighVulnerabilitySecurityCVE-2025-23323NVIDIA Triton Inference Server for Windows and Linux contains CVE-2025-23323, an integer overflow or wraparound that a user can trigger by sending an invalid request. The overflow leads to a segmentation fault, and a successful exploit might cause denial of service. The entry is classified as CWE-190 and was published to NVD on 08/06/2025.
NVD/CVE DatabaseCVE-2025-23322: NVIDIA Triton Inference Server double free when stream is cancelled
Aug 6, 2025HighVulnerabilitySecurityCVE-2025-23322NVIDIA Triton Inference Server for Windows and Linux contains a double free vulnerability (CWE-415). Multiple requests could trigger it when a stream is cancelled before it is processed. A successful exploit might lead to denial of service.
NVD/CVE DatabaseCVE-2025-23321: NVIDIA Triton Inference Server divide by zero from invalid request
Aug 6, 2025HighVulnerabilitySecurityCVE-2025-23321NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability, tracked as CVE-2025-23321 and classified as CWE-369 (Divide By Zero). A user can trigger a divide by zero by sending an invalid request. A successful exploit might lead to denial of service.
NVD/CVE DatabaseCVE-2025-23320: NVIDIA Triton Inference Server Python backend shared memory limit exceeded
Aug 6, 2025HighVulnerabilitySecurityCVE-2025-23320NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend. An attacker could exceed the shared memory limit by sending a very large request, and a successful exploit might lead to information disclosure. The weakness is classified as CWE-209, Generation of Error Message Containing Sensitive Information.
NVD/CVE DatabaseCVE-2025-23319: NVIDIA Triton Inference Server Python backend out-of-bounds write via request
Aug 6, 2025HighVulnerabilitySecurityCVE-2025-23319NVIDIA Triton Inference Server for Windows and Linux contains an out-of-bounds write in its Python backend, which an attacker can trigger by sending a request. The source says a successful exploit might lead to remote code execution, denial of service, data tampering, or information disclosure. The NVD assessment is not yet provided, and the record is tagged CWE-787 and CWE-805.
NVD/CVE DatabaseCVE-2025-23318: NVIDIA Triton Inference Server Python backend out-of-bounds write
Aug 6, 2025HighVulnerabilitySecurityCVE-2025-23318NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write (CWE-787). A successful exploit might lead to code execution, denial of service, data tampering, and information disclosure. NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2025-23317: NVIDIA Triton Inference Server HTTP server reverse shell via crafted request
Aug 6, 2025CriticalVulnerabilitySecurityCVE-2025-23317NVIDIA Triton Inference Server contains a vulnerability in its HTTP server, where an attacker could start a reverse shell by sending a specially crafted HTTP request. The NVD entry states that a successful exploit might lead to remote code execution, denial of service, data tampering, or information disclosure, and it is classified as CWE-122 Heap-based Buffer Overflow.
NVD/CVE DatabaseCVE-2025-23311: NVIDIA Triton Inference Server stack overflow through crafted HTTP requests
Aug 6, 2025CriticalVulnerabilitySecurityCVE-2025-23311CVE-2025-23311 affects NVIDIA Triton Inference Server. An attacker can cause a stack overflow through specially crafted HTTP requests, which CWE-121 classifies as a stack-based buffer overflow. The source says a successful exploit might lead to remote code execution, denial of service, information disclosure, or data tampering.
NVD/CVE DatabaseCVE-2025-23310: NVIDIA Triton Inference Server stack buffer overflow from crafted inputs
Aug 6, 2025CriticalVulnerabilitySecurityCVE-2025-23310NVIDIA Triton Inference Server for Windows and Linux contains a stack buffer overflow, classified as CWE-121, that an attacker can trigger with specially crafted inputs. The source states that a successful exploit might lead to remote code execution, denial of service, information disclosure, and data tampering. NVD had not yet provided an assessment when the entry was published on 08/06/2025.
NVD/CVE DatabaseCVE-2025-51471: Ollama cross-domain token exposure in WWW-Authenticate realm handling
Jul 22, 2025MediumVulnerabilitySecurityCVE-2025-51471EPSS: 15.2%CVE-2025-51471 is a cross-domain token exposure flaw in server.auth.getAuthorizationToken in Ollama 0.6.7. A remote attacker who controls a malicious realm value in a WWW-Authenticate header returned by the /api/pull endpoint can steal authentication tokens and bypass access controls. NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2025-48944: vLLM crash through malformed tool input on /v1/chat/completions
May 30, 2025MediumVulnerabilitySecurityCVE-2025-48944CVE-2025-48944 affects vLLM versions 0.8.0 up to but excluding 0.9.0. The vLLM backend behind the /v1/chat/completions OpenAPI endpoint does not validate unexpected or malformed input in the "pattern" and "type" fields when the tools functionality is invoked. A single crafted request crashes the inference worker, which stays down until it is restarted.
Fix: Fixed in 0.9.0.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.