TensorRTLLM OpenAI API Assertion Trigger Leads to DoS
CVE-2026-47475 Published on July 14, 2026
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread. A successful exploit of this vulnerability might lead to denial of service.
Vulnerability Analysis
CVE-2026-47475 can be exploited with local system access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
What is an assertion failure Vulnerability?
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
CVE-2026-47475 has been classified to as an assertion failure vulnerability or weakness.
Affected Versions
NVIDIA TensorRT-LLM:- Before and including v1.3.0 rc15 is affected.