Impact
NVIDIA Dynamo for Linux includes a flaw in its multimodal media fetcher that allows an attacker to perform server‑side request forgery through DNS rebinding. This bypasses the intended DNS resolution logic and can cause the service to resolve arbitrary DNS names on the attacker’s behalf. The vulnerability is a classic DNS rebinding SSRF (CWE‑918) and could enable access to internal resources or leak sensitive data, thereby compromising confidentiality.
Affected Systems
The affected product is NVIDIA Dynamo for Linux. No specific version information is provided in the CVE data; all versions of the product that include the multimodal media fetcher are potentially impacted.
Risk and Exploitability
The CVSS score of 7.5 categorizes this as a high‑severity vulnerability, although the EPSS score is not available so the current exploitation probability is unclear. The CVE is not listed in the CISA KEV catalog, indicating no known public exploits at this time. The attack vector is inferred to require the attacker to cause the Dynamo service to initiate DNS resolution for malicious or spoofed domain names, which suggests that network controls and proper request validation are critical to preventing exploitation.
OpenCVE Enrichment