Description
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
Published: 2026-07-01
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA Megatron Bridge for Linux contains a flaw that permits an attacker to deserialize untrusted data. This weakness, which follows CWE-94, opens the possibility of arbitrary code execution, privilege escalation, data tampering, and information disclosure.

Affected Systems

All installations of NVIDIA Megatron Bridge for Linux are potentially affected, as no specific version information is provided and any instance of this product should be treated as vulnerable until an official fix is released.

Risk and Exploitability

The CVSS score of 7.8 indicates moderate to high severity, while the EPSS score of < 1% signifies a very low probability of exploitation at present. The vulnerability is not listed in CISA KEV, so it is not known to be actively exploited. The attack vector is not explicitly stated in the description; based on the description, it is inferred that any interface that accepts serialized input and performs unrestricted deserialization could be a potential path for the attacker to execute arbitrary code with the privileges of the Megatron Bridge process.

Generated by OpenCVE AI on July 21, 2026 at 14:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest NVIDIA Megatron Bridge update that contains the deserialization fix when it becomes available.
  • Restrict network access to the component that performs deserialization, using firewall rules or container networking to limit inbound connections to trusted hosts.
  • Validate incoming serialized data against a strict schema or use safe deserialization libraries that reject malformed or unexpected payloads to prevent execution of attacker‑crafted data.

Generated by OpenCVE AI on July 21, 2026 at 14:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge for Linux

Fri, 17 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge for Linux

Wed, 15 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Untrusted Deserialization Leading to Remote Code Execution in NVIDIA Megatron Bridge

Mon, 13 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Untrusted Deserialization Leading to Remote Code Execution in NVIDIA Megatron Bridge

Sat, 11 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge for Linux Leading to Code Execution

Fri, 10 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge for Linux Leading to Code Execution

Fri, 10 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge

Thu, 09 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge

Wed, 08 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge for Linux

Wed, 08 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge for Linux

Tue, 07 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge Enables Remote Code Execution

Tue, 07 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge Enables Remote Code Execution

Mon, 06 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability Enabling Code Execution in NVIDIA Megatron Bridge for Linux

Sun, 05 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability Enabling Code Execution in NVIDIA Megatron Bridge for Linux

Sun, 05 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge Allows Remote Code Execution and Privilege Escalation

Sat, 04 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge Allows Remote Code Execution and Privilege Escalation

Sat, 04 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge Leading to Remote Code Execution

Fri, 03 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge Leading to Remote Code Execution

Fri, 03 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge Allows Arbitrary Code Execution

Fri, 03 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge Allows Arbitrary Code Execution

Thu, 02 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability Enables Remote Code Execution in NVIDIA Megatron Bridge

Thu, 02 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability Enables Remote Code Execution in NVIDIA Megatron Bridge

Thu, 02 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge for Linux Enabling Code Execution and Privilege Escalation

Wed, 01 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia megatron-bridge
Vendors & Products Nvidia
Nvidia megatron-bridge

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Megatron Bridge for Linux Enabling Code Execution and Privilege Escalation

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Nvidia Megatron-bridge
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-07-01T15:57:54.343Z

Reserved: 2026-01-21T19:09:47.375Z

Link: CVE-2026-24249

cve-icon Vulnrichment

Updated: 2026-07-01T15:57:51.314Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T14:15:04Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')