NVIDIA Product Security Team

10 exploits Active since Jul 2026
CVE-2026-24254 WRITEUP CRITICAL WRITEUP
Nvidia Dynamo - Authentication Bypass Using an Alternate Path or Channel
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
CVSS 9.8
CVE-2026-47487 WRITEUP MEDIUM WRITEUP
Nvidia Triton Inference Server - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
CVSS 4.4
CVE-2026-47615 WRITEUP HIGH WRITEUP
Nvidia Dynamo - Server-Side Request Forgery (SSRF)
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
CVSS 7.5
CVE-2026-47616 WRITEUP HIGH WRITEUP
Nvidia Dynamo - Server-Side Request Forgery (SSRF)
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CVSS 7.5
CVE-2026-47617 WRITEUP HIGH WRITEUP
Nvidia Dynamo - Server-Side Request Forgery (SSRF)
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.
CVSS 7.5
CVE-2026-47618 WRITEUP HIGH WRITEUP
Nvidia Dynamo - Server-Side Request Forgery (SSRF)
NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CVSS 7.5
CVE-2026-47621 WRITEUP MEDIUM WRITEUP
Nvidia Dynamo - Time-of-check Time-of-use (TOCTOU) Race Condition
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CVSS 6.5
CVE-2026-47622 WRITEUP MEDIUM WRITEUP
Nvidia Dynamo - Generation of Error Message Containing Sensitive Information
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure.
CVSS 5.3
CVE-2026-47483 WRITEUP HIGH WRITEUP
Nvidia Dcgm - Allocation of Resources Without Limits or Throttling
NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
CVSS 8.2
CVE-2026-24232 WRITEUP MEDIUM STUB
Nvidia Tranformers4Rec - Deserialization of Untrusted Data
NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVSS 4.3