Description
NVIDIA Model-Optimizer contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
Published: 2026-10-06
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

NVIDIA Model-Optimizer is vulnerable to unsafe deserialization of untrusted data, which may allow an attacker to run arbitrary code, modify data, disrupt service availability, or leak sensitive information. The weakness is identified as CWE-502, a common deserialization flaw that can be leveraged to achieve these outcomes when an attacker controls the input stream.

Affected Systems

The vulnerability affects NVIDIA’s Model-Optimizer component. No specific version ranges are disclosed; therefore, users of any releases that have not yet been patched remain at risk.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity level, and although no EPSS data is available, the potential for exploitation remains significant because the flaw permits code execution when untrusted data is processed. The vulnerability is not currently listed in the CISA KEV catalog, but its impact warrants close monitoring. The likely attack vector is through submission of crafted input to the Model-Optimizer, which could be achieved remotely if the service is exposed or locally if an attacker can supply input via an insider or compromised system.

Generated by OpenCVE AI on October 7, 2026 at 00:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest NVIDIA Model-Optimizer release that fixes the unsafe deserialization issue.
  • Configure access controls to restrict who can send input to the Model-Optimizer, limiting exposure to trusted users or network segments.
  • Implement input validation or use a secure deserialization library to ensure only properly structured data is processed.

Generated by OpenCVE AI on October 7, 2026 at 00:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in NVIDIA Model-Optimizer May Enable Code Execution

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Description NVIDIA Model-Optimizer contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-10-06T21:03:15.565Z

Reserved: 2026-07-21T17:28:38.791Z

Link: CVE-2026-65142

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T22:17:07.430

Modified: 2026-10-06T22:17:07.430

Link: CVE-2026-65142

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T00:15:07Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data