Impact
NVIDIA Megatron Bridge for Linux contains a vulnerability that allows an attacker to trigger server‑side request forgery. The flaw enables the appliance to forward requests on behalf of the attacker to arbitrary internal endpoints, potentially exposing sensitive data. The weakness corresponds to CWE‑918.
Affected Systems
All deployments of NVIDIA Megatron Bridge for Linux running unpatched versions are potentially vulnerable. The CVE data does not enumerate specific affected releases, so the assumption is that all current builds remain at risk until a vendor‑supplied fix is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high threat to confidentiality. The EPSS score of less than 1 % suggests a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. To exploit this flaw an attacker would need network access to the bridge’s interface; the attack vector is inferred to be network‑based from the description.
OpenCVE Enrichment