ZDI-26-061: NVIDIA Triton Inference Server EVBufferToJson Uncaught Exception Denial-of-Service Vulnerability
Published Feb 4, 2026
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of NVIDIA Triton Inference Server. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2025-33201.
Affected Software
1 affected component
Nvidia Triton Inference Server
Event History
Feb 4, 2026
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-061?
ZDI-26-061 is classified as a high-severity denial-of-service vulnerability.
2
How do I fix ZDI-26-061?
To remediate ZDI-26-061, update your NVIDIA Triton Inference Server to the latest patched version provided by NVIDIA.
3
Who can exploit ZDI-26-061?
ZDI-26-061 can be exploited by remote attackers without requiring authentication.
4
What type of vulnerability is ZDI-26-061?
ZDI-26-061 is an uncaught exception denial-of-service vulnerability.
5
Which software is affected by ZDI-26-061?
ZDI-26-061 affects NVIDIA Triton Inference Server installations.