NVIDIA Model Optimizer: RCE via unsafe deserialization
CVSS 7.8CVE-2026-24141NVIDIA / GPU stackcurated
Impact
RCE via unsafe deserialization
Who can reach it
Malicious model artifact
What to do
Bump ModelOpt; rebuild optimization images
References
Related entries
- NVIDIA Megatron-LM: A further script-level code-injection path, filed under the same class as the 2025 setCVE-2026-24149 · NVIDIA Megatron-LMHigh
- NVIDIA Megatron-LM: Checkpoint loading reaches remote code execution when a user loads a crafted checkpointCVE-2026-24150 · NVIDIA Megatron-LMHigh
- NVIDIA Megatron-LM: The inferencing path reaches remote code execution on crafted inputCVE-2026-24151 · NVIDIA Megatron-LMHigh
- NVIDIA Megatron-LM: A second checkpoint-loading remote code execution pathCVE-2026-24152 · NVIDIA Megatron-LMHigh
- NeMo Framework: RCE via malicious YAML deserializationCVE-2026-24155 · NeMo FrameworkHigh
- NeMo Framework: unsafe deserialization of untrusted model data allows remote code executionCVE-2026-24157 · NeMo FrameworkHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.