CVE-2025-23317
critical · 9.1NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specially crafted HTTP request. A successful exploit of this vulnerability might lead to remote code execution, denial of service, data tampering, or information disclosure.
9.1
CVSS
2.0%
EPSS (exploit prob.)
80th
EPSS percentile
2025-08-06
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Weaknesses
CWE-122
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| nvidia | triton_inference_server | < 25.07 |
| linux | linux_kernel | all versions |
| microsoft | windows | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-23317