Description
NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA Transformers4Rec is vulnerable to improper deserialization of untrusted data. A successful exploit may allow an attacker to run arbitrary code in the context of the affected system, and could also lead to data tampering and information disclosure.

Affected Systems

The vulnerability affects NVIDIA Transformers4Rec. No specific version information is provided in the advisory, so all deployed instances of this product should be considered potentially impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, indicating it has not been widely reported as exploited. The likely attack vector is remote delivery of malicious serialized data, although the exact prerequisites are not detailed in the advisory. The impact remains significant due to the risk of code execution and data compromise.

Generated by OpenCVE AI on July 30, 2026 at 17:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update NVIDIA Transformers4Rec to the latest version once the vendor releases a fix for the deserialization issue.
  • Configure the application or its environment to disable or restrict any functionality that processes external serialized data, if possible.
  • Implement monitoring for deserialization failures or abnormal activity that could indicate an attempted exploitation.

Generated by OpenCVE AI on July 30, 2026 at 17:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Improper Deserialization in NVIDIA Transformers4Rec Enables Code Execution

Wed, 29 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Improper Deserialization in NVIDIA Transformers4Rec Allows Code Execution

Fri, 24 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Improper Deserialization in NVIDIA Transformers4Rec Allows Code Execution

Tue, 21 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia transformers4rec
Vendors & Products Nvidia
Nvidia transformers4rec

Tue, 21 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L'}


Subscriptions

Nvidia Transformers4rec
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-07-21T17:19:03.845Z

Reserved: 2026-01-21T19:09:37.972Z

Link: CVE-2026-24232

cve-icon Vulnrichment

Updated: 2026-07-21T17:17:56.815Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:15:12Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data