Description
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
Published: 2026-08-04
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA Dynamo for Linux contains a server‑side request forgery flaw in its multimodal media fetcher. The vulnerability allows an attacker to compel the server to make arbitrary HTTP requests, potentially exposing internal or external resources. Successful exploitation could lead to information disclosure, compromising confidentiality. This issue is classified as CWE‑918, reflecting the injection of arbitrary URLs into server‑side requests.

Affected Systems

The flaw affects NVIDIA Dynamo for Linux deployments; no specific product versions are currently listed as impacted. Any installation that includes the multimodal media fetcher is potentially vulnerable until a vendor patch or mitigation is applied.

Risk and Exploitability

The CVSS score of 7.5 indicates moderate to high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that public exploitation has not yet been observed. Based on the description, it is inferred that the attack vector is remote, requiring network reach to the NVIDIA Dynamo instance. The potential impact is information disclosure, but the likelihood of exploitation remains uncertain without known public exploits.

Generated by OpenCVE AI on August 4, 2026 at 19:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check NVIDIA’s product security portal and apply the latest patch for Dynamo as soon as it is released.
  • Limit the network exposure of the Dynamo service to trusted networks or use a reverse proxy to block unsolicited requests.
  • Configure any available settings to validate URLs or whitelist domains that the multimodal media fetcher is allowed to request, thereby reducing the SSRF risk.

Generated by OpenCVE AI on August 4, 2026 at 19:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia dynamo
Vendors & Products Nvidia
Nvidia dynamo

Tue, 04 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery in NVIDIA Dynamo for Linux

Tue, 04 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-04T18:35:54.091Z

Reserved: 2026-05-19T19:55:51.495Z

Link: CVE-2026-47616

cve-icon Vulnrichment

Updated: 2026-08-04T18:35:49.971Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T18:16:51.120

Modified: 2026-08-07T19:05:56.730

Link: CVE-2026-47616

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:19:28Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)