GPU VulnDB

Database/AI/ML frameworks & serving

NVIDIA Megatron Bridge: deserialization of untrusted data allows code execution in the training job

CVE-2026-61757AI/ML frameworks & servingcurated

Impact

The last of eight deserialization flaws in the same NVIDIA bulletin: untrusted serialized data handled by Megatron Bridge can lead to code execution, data tampering, and information disclosure. Code runs with the training job's privileges on a GPU node, reaching the GPUs, mounted training data and checkpoints, and job credentials. Because all eight share one fixed version, treat them as a single upgrade decision rather than eight separate ones. NVIDIA does not document which input path each CVE covers.

Who can reach it

Local, low privileges required, no user interaction - anyone who can supply a serialized artifact that Megatron Bridge loads on the node.

What to do

Upgrade Megatron Bridge to 0.5.1; versions 0.0 through 0.5.0 are affected, and the same bump closes all eight CVEs in this bulletin. Rebuild training images and restart jobs. No node drain, reboot, or firmware step is required.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.