NVIDIA TensorRT-LLM gRPC Chat API CWE-20 Local Attack
CVE-2026-47470 Published on July 14, 2026
NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A successful exploit of this vulnerability might lead to denial of service.
Vulnerability Analysis
CVE-2026-47470 is exploitable with local system access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Affected Versions
NVIDIA TensorRT-LLM:- Before and including v1.3.0 rc14 is affected.