Transformers4Rec: Code exec via insecure deserialization in the pipeline
CVSS 4.3CVE-2026-24232NVIDIA / GPU stackcurated
Impact
Code exec via insecure deserialization in the pipeline
Who can reach it
Malicious dataset/model
What to do
Bump the package; rebuild recsys images
References
Related entries
- NVIDIA License System - Delegated Licensing Service (DLS): Improper authentication in the DLS lets an unauthenticatedCVE-2026-24241 · NVIDIA License System - Delegated Licensing Service (DLS)Medium
- GeForce NOW Android app: Info disclosure / code exec via implicit intentCVE-2023-31014 · GeForce NOW Android appMedium
- DGX A100 SBIOS: Buffer overflow in SBIOSCVE-2023-31031 · DGX A100 SBIOSMedium
- Mellanox OS / MetroX / Onyx / Skyway: Improper access control on switch mgmtCVE-2024-0104 · Mellanox OS / MetroX / Onyx / SkywayMedium
- CUDA Toolkit: Code exec potential (buffer overflow)CVE-2025-23275 · CUDA ToolkitMedium
- NVIDIA HGX / DGX (Hopper and Blackwell) - GPU VBIOS: A VBIOS misconfiguration lets an attacker set an unsafe GPU debugCVE-2025-23301 · NVIDIA HGX / DGX (Hopper and Blackwell) - GPU VBIOSMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.