NVIDIA PSIRT

14 exploits Active since Jul 2026
CVE-2025-23350 WRITEUP CRITICAL WRITEUP
Nvidia BlueField GA - Out-of-bounds Write
NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.
CVSS 9.0
CVE-2026-24240 WRITEUP HIGH WRITEUP
Nvidia Megatron-Bridge - Deserialization of Untrusted Data
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVSS 7.8
CVE-2026-24242 WRITEUP HIGH WRITEUP
Nvidia Megatron-Bridge - Server-Side Request Forgery (SSRF)
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CVSS 7.8
CVE-2026-24243 WRITEUP HIGH WRITEUP
Nvidia Megatron-Bridge - Deserialization of Untrusted Data
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVSS 7.8
CVE-2026-24245 WRITEUP HIGH WRITEUP
Nvidia Megatron-Bridge - Deserialization of Untrusted Data
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVSS 7.8
CVE-2026-24246 WRITEUP HIGH WRITEUP
Nvidia Megatron-Bridge - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVSS 7.8
CVE-2026-24247 WRITEUP HIGH WRITEUP
Nvidia Megatron-Bridge - Deserialization of Untrusted Data
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVSS 7.8
CVE-2026-24248 WRITEUP HIGH WRITEUP
Nvidia Megatron-Bridge - Improper Control of Generation of Code ('Code Injection')
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVSS 7.8
CVE-2026-24249 WRITEUP HIGH WRITEUP
Nvidia Megatron-Bridge - Improper Control of Generation of Code ('Code Injection')
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVSS 7.8
CVE-2026-24250 WRITEUP HIGH WRITEUP
Nvidia Megatron-Bridge - Deserialization of Untrusted Data
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVSS 7.8
CVE-2026-24251 WRITEUP HIGH WRITEUP
Nvidia Megatron-Bridge - Deserialization of Untrusted Data
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVSS 7.8
CVE-2026-24260 WRITEUP HIGH WRITEUP
Nvidia Container Toolkit - Time-of-check Time-of-use (TOCTOU) Race Condition
NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and data tampering.
CVSS 8.5
CVE-2026-24266 WRITEUP MEDIUM WRITEUP
Nvidia Triton Inference Server - Use After Free
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service.
CVSS 5.9
CVE-2026-24270 WRITEUP CRITICAL WRITEUP
Nvidia AIStore Framework - Authentication Bypass by Spoofing
NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.
CVSS 9.8