CVE-2026-24233: NVIDIA Tensorrt-Llm
High severity, CVSS 8.4. EPSS: 0.4% chance of exploitation in the next 30 days.
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
Affected products
- NVIDIA Tensorrt-Llm: from 0.0, up to and including v1.3.0 rc14
Published 2026-07-14. Last modified 2026-07-15.