NVIDIA Dynamo: Error messages from Dynamo leak sensitive information to an unauthenticated network caller
CVSS 5.3CVE-2026-47622NVIDIA / GPU stackcurated
Impact
Error messages from Dynamo leak sensitive information to an unauthenticated network caller - typically internal paths, versions and configuration that shorten the next stage of an attack.
Who can reach it
Network, unauthenticated. Anyone who can reach the Dynamo serving endpoint and provoke an error.
What to do
Upgrade Dynamo per bulletin 5842 and roll the deployment. Cost: rolling restart of the serving tier.
References
Related entries
- NVIDIA Dynamo: Unauthenticated remote code executionCVE-2026-24254 · NVIDIA DynamoCritical
- NVIDIA Dynamo: RCE via buffer overflow in tensor shape validationCVE-2026-24253 · NVIDIA DynamoHigh
- NVIDIA Dynamo: Deserialization of untrusted data in Dynamo reaches denial of service and data tamperingCVE-2026-47623 · NVIDIA DynamoHigh
- NVIDIA Dynamo: MITM via improper TLS certificate verificationCVE-2026-24255 · NVIDIA DynamoHigh
- NVIDIA Dynamo: Arbitrary file access via path traversalCVE-2026-47612 · NVIDIA DynamoHigh
- NVIDIA Dynamo: SSRF via URL handlingCVE-2026-47613 · NVIDIA DynamoHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.