June 4th, 2026

Batch Container

Realtime Container

15.9.0 Containers

Version 15.9.0 is now available for Batch Container, Real-Time Container, GPU Transcription Inference Container and GPU Translation Inference Container.

New


GPU & CPU

HTTP Batch Transcription

  • Supports URL-based audio input. Users can provide an audio file URL, enabling the service to fetch the file for transcription. See the documentation for more details.

  • The /ready endpoint now reports engines_used, improving service visibility. See the documentation for more details.

Improvements


CPU

  • New Arabic models (Enhanced Operating Point) give up to 2.7% relative accuracy improvement.

Fixes


GPU & CPU

  • Fixed transcription job failures when speaker diarization was enabled for WAV files with missing or incorrect duration metadata.

  • Fixed failure to generate transcripts for a small number of stereo files when one channel contains leading silence.

Security fixes


Vulnerability Management

  • Software Bill of Materials (SBOM) is available for download from the corresponding release page in our Support Portal.

  • libgstreamer (CVE-2025-3887): This component has been manually patched to address CVE-2025-3887. Note: Security scanners may still flag this component as vulnerable because the base version string remains unchanged

  • tritonserver 2.61.0 (NGC 25.09): This is a component in sm-gpu-inference-server and sm-translation-server images that is not listed in the corresponding SBOMs due to lack of installation metadata in the base images published by Nvidia.

    The identified CVEs have been reviewed and are not considered exploitable, provided the Triton API is only accessible to transcriber containers within the same trust domain. This can be achieved by deploying STT in a private Kubernetes cluster or by using a service mesh to restrict access to the appropriate pods.

    A future release will rebuild against Nvidia NGC 26.03 or later with the relevant fixes.

Identified CVEs

Severity

CVE-2026-24207

CRITICAL: Mar 2026 bulletin (a_id 5790), fixed in NGC 26.03

CVE-2026-24206, CVE-2026-24208, CVE-2026-24209, CVE-2026-24210, CVE-2026-24213, CVE-2026-24214

HIGH: Mar 2026 bulletin (a_id 5790), fixed in NGC 26.03

CVE-2026-24215

HIGH: May 2026 bulletin (a_id 5828), fixed in NGC 26.03

CVE-2026-24146, CVE-2026-24147, CVE-2026-24173, CVE-2026-24174, CVE-2026-24175

HIGH: Apr 2026 bulletin (a_id 5816), fixed in NGC 26.02

CVE-2025-33201, CVE-2025-33211

HIGH: Dec 2025 bulletin (a_id 5734), fixed post-25.09