Threat Advisory

NVIDIA Dynamo Flaw Lets Attackers Execute Arbitrary Code

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting NVIDIA Dynamo for Linux versions These vulnerabilities impact various builds of NVIDIA Dynamo for Linux, a product that plays a key role in artificial intelligence workflows and is relied upon by many enterprise organizations. The most severe vulnerability carries a maximum CVSS score of 9.8. Affected versions include various builds from 0 to v1.2.0.

CVE-2026-24254 (CVSS 9.8 — Critical): NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting NVIDIA Dynamo for Linux versions These vulnerabilities impact various builds of NVIDIA Dynamo for Linux, a product that plays a key role in artificial intelligence workflows and is relied upon by many enterprise organizations. The most severe vulnerability carries a maximum CVSS score of 9.8. Affected versions include various builds from 0 to v1.2.0.

CVE-2026-24254 (CVSS 9.8 — Critical): NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.[emaillocker id="1283"]

CVE-2026-24253 (CVSS 8.2 — High): NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.

CVE-2026-47623 (CVSS 8.2 — High): NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.

CVE-2026-24255 (CVSS 7.5 — Medium): NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.

CVE-2026-47612 (CVSS 7.5 — Medium): NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure.

CVE-2026-47613 (CVSS 7.5 — Medium): NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.

CVE-2026-47614 (CVSS 7.5 — Medium): NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.

CVE-2026-47615 (CVSS 7.5 — Medium): NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.

These vulnerabilities collectively present a significant risk to enterprise organizations relying on NVIDIA Dynamo for Linux.

RECOMMENDATION:

We recommend you to update NVIDIA Dynamo to version 1.1.1, 1.2.0, or 1.3.0.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu