Description
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.
Published: 2026-08-04
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA Dynamo for Linux includes a flaw that permits deserialization of untrusted data, a weakness identified as CWE‑502. When an attacker supplies crafted input, the system may incorrectly interpret it, leading to unexpected behavior. The documented effects are denial of service and tampering of data stored or processed by the Dynamo application.

Affected Systems

The vulnerability affects NVIDIA Dynamo for Linux. The specific affected versions are not enumerated in the available information.

Risk and Exploitability

The CVSS score of 8.2 classifies this as a high‑severity vulnerability, indicating significant potential impact on integrity and availability. No EPSS score is available, so the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploit in the wild at this time. The attack vector is likely to involve an attacker delivering malicious data to Dynamo’s input interfaces; this inference is drawn from the description that mentions deserialization of untrusted data, but the precise method of delivery is not specified in the source.

Generated by OpenCVE AI on August 4, 2026 at 20:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update NVIDIA Dynamo to a release that contains the deserialization fix, as noted in the NVIDIA product security advisory
  • Restrict file permissions and validate inputs to the Dynamo application to reduce exposure to untrusted data
  • Monitor for deserialization errors or abnormal input patterns in logs to detect potential exploitation attempts

Generated by OpenCVE AI on August 4, 2026 at 20:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia dynamo
Vendors & Products Nvidia
Nvidia dynamo

Tue, 04 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Dynamo for Linux Leading to Denial of Service and Data Tampering

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-04T17:58:07.105Z

Reserved: 2026-05-19T19:55:52.529Z

Link: CVE-2026-47623

cve-icon Vulnrichment

Updated: 2026-08-04T17:58:03.409Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T18:16:51.983

Modified: 2026-08-07T17:03:21.317

Link: CVE-2026-47623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:19:16Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data