CVE-2025-23316·Python vulnerability
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause a remote code execution by manipulating the model name parameter in the model control APIs. A successful exploit of this vulnerability might lead to remote code execution, denial of service, information disclosure, and data tampering.
- Severity
- critical
- Software
- Python
- Fixed in
- 25.08
- Published
- 2025-09-17
Affected versions
Until: 25.08
Fixed in: 25.08
How to fix this CVE
Update NVIDIA Triton Inference Server to version 25.08 or later to patch the Python backend model name parameter vulnerability. Organizations running Triton with the Python backend should prioritize this update immediately, as the vulnerability allows unauthenticated remote code execution. Verify the updated version is deployed across all inference servers before resuming production traffic.
sudo dnf check-update python3 && sudo dnf upgrade python3Defensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST requests to /v2/models/{MODEL_NAME}/config or /v2/models/{MODEL_NAME}/load with model name parameters containing shell metacharacters (;|&$`\n) or path traversal sequences (../) should be flagged as potential exploitation attemptsWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement strict input validation on all model name parameters accepted by Triton's model control APIs, restricting to alphanumeric characters, hyphens, and underscores only. Rate-limit requests to /v2/models/*/config and /v2/models/*/load endpoints to 10 requests per minute per source IP.How to check if you are affected
- Run 'python3 --version' to confirm the current Python version installed on the system
- Check if NVIDIA Triton Inference Server is running via 'ps aux | grep tritonserver' and verify the deployment version
- Review Triton server logs for unexpected model loading attempts or malformed model names: 'grep -i "model" /var/log/triton/*.log | grep -E "(error|exception|traceback)"'
- Confirm the Triton version is 25.08 or later by checking the server info endpoint: 'curl -s http://localhost:8000/v2/health/ready | grep -o version'
FAQ
What is CVE-2025-23316?
CVE-2025-23316 is a critical remote code execution vulnerability in NVIDIA Triton Inference Server's Python backend that allows attackers to inject malicious code through crafted model name parameters in the model control APIs, bypassing authentication entirely.
Is CVE-2025-23316 being actively exploited?
According to CISA, this vulnerability is not currently listed in the Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available, though the critical CVSS score of 9.8 warrants immediate patching.
What versions of Python are affected by CVE-2025-23316?
All versions of NVIDIA Triton Inference Server up to and including version 25.07 that use the Python backend are affected; version 25.08 and later contain the fix.
How do I check if my server is vulnerable to CVE-2025-23316?
Run 'tritonserver --version' to confirm your Triton version; if it is below 25.08, your system is vulnerable. Additionally, check if the Python backend is enabled in your model configuration files.
Does Defensia detect CVE-2025-23316?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Python or NVIDIA Triton is installed on a monitored server, CVE-2025-23316 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-23316. Free for 1 server.
Get started free