Multiple security vulnerabilities affecting NVIDIA Dynamo for Linux versions These vulnerabilities impact various builds of NVIDIA Dynamo for Linux, a product that plays a key role in artificial intelligence workflows and is relied upon by many enterprise organizations. The most severe vulnerability carries a maximum CVSS score of 9.8. Affected versions include various builds from 0 to v1.2.0.
CVE-2026-24254 (CVSS 9.8 — Critical): NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting NVIDIA Dynamo for Linux versions These vulnerabilities impact various builds of NVIDIA Dynamo for Linux, a product that plays a key role in artificial intelligence workflows and is relied upon by many enterprise organizations. The most severe vulnerability carries a maximum CVSS score of 9.8. Affected versions include various builds from 0 to v1.2.0.
CVE-2026-24254 (CVSS 9.8 — Critical): NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.[emaillocker id="1283"]
CVE-2026-24253 (CVSS 8.2 — High): NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CVE-2026-47623 (CVSS 8.2 — High): NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CVE-2026-24255 (CVSS 7.5 — Medium): NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.
CVE-2026-47612 (CVSS 7.5 — Medium): NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47613 (CVSS 7.5 — Medium): NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47614 (CVSS 7.5 — Medium): NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-47615 (CVSS 7.5 — Medium): NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
These vulnerabilities collectively present a significant risk to enterprise organizations relying on NVIDIA Dynamo for Linux.
We recommend you to update NVIDIA Dynamo to version 1.1.1, 1.2.0, or 1.3.0.
The following reports contain further technical details:
[/emaillocker]