CVE-2026-24233: NVIDIA Tensorrt-Llm

High severity, CVSS 8.4. EPSS: 0.4% chance of exploitation in the next 30 days.

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

Affected products

  • NVIDIA Tensorrt-Llm: from 0.0, up to and including v1.3.0 rc14

Published 2026-07-14. Last modified 2026-07-15.