NVIDIA Dynamo: Unauthenticated remote code execution
CVSS 9.8CVE-2026-24254NVIDIA / GPU stackcurated
Impact
Unauthenticated remote code execution
Who can reach it
Network-adjacent unauthenticated
What to do
Emergency Dynamo upgrade; redeploy; gate endpoints behind authn and network policy
References
Related entries
- NVIDIA Dynamo: RCE via buffer overflow in tensor shape validationCVE-2026-24253 · NVIDIA DynamoHigh
- NVIDIA Dynamo: Deserialization of untrusted data in Dynamo reaches denial of service and data tamperingCVE-2026-47623 · NVIDIA DynamoHigh
- NVIDIA Dynamo: MITM via improper TLS certificate verificationCVE-2026-24255 · NVIDIA DynamoHigh
- NVIDIA Dynamo: Arbitrary file access via path traversalCVE-2026-47612 · NVIDIA DynamoHigh
- NVIDIA Dynamo: SSRF via URL handlingCVE-2026-47613 · NVIDIA DynamoHigh
- NVIDIA Dynamo: SSRF in remote resource loadingCVE-2026-47614 · NVIDIA DynamoHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.