ZDI-CAN-26889: ZDI-26-061: NVIDIA Triton Inference Server EVBufferToJson Uncaught Exception Denial-of-Service Vulnerability
Published Feb 4, 2026
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of NVIDIA Triton Inference Server. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2025-33201.
Affected Software
1 affected component
Nvidia Triton Inference Server
Event History
Feb 4, 2026
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-26889?
The severity of ZDI-CAN-26889 is classified as a denial-of-service vulnerability.
2
How do I fix ZDI-CAN-26889?
To fix ZDI-CAN-26889, you should apply the latest security patches provided by NVIDIA for the Triton Inference Server.
3
What systems are affected by ZDI-CAN-26889?
ZDI-CAN-26889 affects installations of the NVIDIA Triton Inference Server.
4
Can ZDI-CAN-26889 be exploited without authentication?
Yes, ZDI-CAN-26889 can be exploited by remote attackers without requiring authentication.
5
What type of attack does ZDI-CAN-26889 facilitate?
ZDI-CAN-26889 facilitates a denial-of-service condition on affected installations.